PT-2023-17413 · Checkmk · Checkmk
CVE-2023-2020
·
Publicado
2023-04-18
·
Atualizado
2024-07-23
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Checkmk versions prior to 2.1.0p27
Checkmk versions prior to 2.2.0b4
Description
The issue is related to insufficient permission checks in the REST API, allowing unauthorized users to schedule downtimes for any host.
Recommendations
For versions prior to 2.1.0p27, update to a version that includes the necessary permission checks.
For versions prior to 2.2.0b4, update to a version that includes the necessary permission checks.
Correção
Incorrect Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Checkmk