PT-2023-23233 · Checkmk · Checkmk

Jan-Philipp Litza

·

Publicado

2023-12-13

·

Atualizado

2024-07-23

·

CVE-2023-31210

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Checkmk versions 2.2.0p10 through 2.2.0p16
Description The issue concerns the usage of user-controlled LD LIBRARY PATH in the agent of Checkmk, allowing a malicious Checkmk site user to escalate rights via the injection of malicious libraries.
Recommendations For Checkmk versions 2.2.0p10 through 2.2.0p16, consider restricting access to the LD LIBRARY PATH environment variable to prevent malicious library injections until a patch is available. As a temporary workaround, disabling the use of user-controlled LD LIBRARY PATH in the agent can help minimize the risk of exploitation.

Correção

Uncontrolled Search Path Element

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-31210

Produtos afetados

Checkmk