PT-2023-15524 · Checkmk · Checkmk

Stefan Schiller

·

Published

2023-02-20

·

Updated

2024-07-23

·

CVE-2022-47909

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Checkmk versions 1.6.0 through 2.1.0p11 Checkmk versions 2.0.0 through 2.0.0p28
Description The issue allows an attacker to perform direct queries to the application's core from localhost by injecting Livestatus Query Language (LQL) in the AuthUser HTTP query header.
Recommendations For Checkmk versions 1.6.0 through 2.1.0p11, update to a version later than 2.1.0p11. For Checkmk versions 2.0.0 through 2.0.0p28, update to a version later than 2.0.0p28. As a temporary workaround, consider restricting access to the AuthUser HTTP query header until a patch is available.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-47909

Affected Products

Checkmk