PT-2023-15698 · Checkmk · Checkmk

Jan Hörsch

·

Published

2023-02-20

·

Updated

2024-07-23

·

CVE-2022-48320

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Checkmk versions 1.6.0 and earlier Checkmk versions 2.0.0 through 2.0.0p31 Checkmk versions 2.1.0 through 2.1.0p17
Description The issue allows an attacker to perform Cross-site Request Forgery (CSRF) attacks, enabling them to add new visual elements to multiple pages. This can be achieved by exploiting the CSRF weakness in the affected Checkmk versions.
Recommendations For Checkmk versions 1.6.0 and earlier, update to a version that is still supported and has the fix for this issue. For Checkmk versions 2.0.0 through 2.0.0p31, update to version 2.0.0p32 or later. For Checkmk versions 2.1.0 through 2.1.0p17, update to version 2.1.0p18 or later.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2022-48320

Affected Products

Checkmk