Tribe29
Tribe29 Checkmk: vulnerabilidades y CVE
Tribe29 Checkmk tiene 14 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-6740 | Alta (7.8) | 0.18% | — | 12 ene 2024 | Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges |
| CVE-2023-6735 | Alta (7.8) | 0.28% | — | 12 ene 2024 | Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges |
| CVE-2023-31211 | Media (6.5) | 0.51% | — | 12 ene 2024 | Insufficient authentication flow in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows attacker to use locked credentials |
| CVE-2023-31209 | Alta (8.8) | 1.1% | — | 10 ago 2023 | Improper neutralization of active check command arguments in Checkmk < 2.1.0p32, < 2.0.0p38, < 2.2.0p4 leads to arbitrary command execution for authenticated users. |
| CVE-2023-22348 | Media (4.3) | 0.59% | — | 17 may 2023 | Improper Authorization in RestAPI in Checkmk GmbH's Checkmk versions <2.1.0p28 and <2.2.0b8 allows remote authenticated users to read arbitrary host_configs. |
| CVE-2023-31208 | Alta (8.8) | 0.97% | — | 17 may 2023 | Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for authorized users. |
| CVE-2023-22294 | Alta (8.8) | 0.68% | — | 18 abr 2023 | Privilege escalation in Tribe29 Checkmk Appliance before 1.6.4 allows authenticated site users to escalate privileges via incorrectly set permissions. |
| CVE-2023-1768 | Media (5.3) | 0.91% | — | 4 abr 2023 | Inappropriate error handling in Tribe29 Checkmk <= 2.1.0p25, <= 2.0.0p34, <= 2.2.0b3 (beta), and all versions of Checkmk 1.6.0 causes the symmetric encryption of agent data to fail silently and transmit the data in… |
| CVE-2023-22288 | Media (5.4) | 0.40% | — | 20 mar 2023 | HTML Email Injection in Tribe29 Checkmk <=2.1.0p23; <=2.0.0p34, and all versions of Checkmk 1.6.0 allows an authenticated attacker to inject malicious HTML into Emails |
| CVE-2023-0284 | Alta (8.1) | 0.93% | — | 26 ene 2023 | Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDAP user IDs to manipulate files on the server. Checkmk <= 2.1.0p19, Checkmk <= 2.0.0p32, and all versions of Checkmk… |
| CVE-2022-33912 | Alta (7.8) | 0.20% | — | 17 jun 2022 | A permission issue affects users that deployed the shipped version of the Checkmk Debian package. Packages created by the agent bakery (enterprise editions only) were not affected. Using the shipped version of the… |
| CVE-2022-31258 | Media (6.7) | 0.40% | — | 20 may 2022 | In Checkmk before 1.6.0p29, 2.x before 2.0.0p25, and 2.1.x before 2.1.0b10, a site user can escalate to root by editing an OMD hook symlink. |
| CVE-2021-40906 | Media (6.1) | 0.99% | — | 25 mar 2022 | CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a backdoor on the device… |
| CVE-2021-40905 | Alta (8.8) | 3.0% | — | 25 mar 2022 | The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which are Extension Packages, making remote code execution possible.… |