PT-2023-17413 · Checkmk · Checkmk
Published
2023-04-18
·
Updated
2024-07-23
·
CVE-2023-2020
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Checkmk versions prior to 2.1.0p27
Checkmk versions prior to 2.2.0b4
Description
The issue is related to insufficient permission checks in the REST API, allowing unauthorized users to schedule downtimes for any host.
Recommendations
For versions prior to 2.1.0p27, update to a version that includes the necessary permission checks.
For versions prior to 2.2.0b4, update to a version that includes the necessary permission checks.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Checkmk