PT-2023-23231 · Checkmk · Checkmk
Published
2023-05-17
·
Updated
2024-07-23
·
CVE-2023-31208
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Checkmk versions prior to 2.0.0p36
Checkmk versions prior to 2.1.0p28
Checkmk versions prior to 2.2.0b8
Description
The issue is related to the improper neutralization of livestatus command delimiters in the RestAPI, allowing arbitrary livestatus command execution for authorized users.
Recommendations
For versions prior to 2.0.0p36, update to version 2.0.0p36 or later.
For versions prior to 2.1.0p28, update to version 2.1.0p28 or later.
For versions prior to 2.2.0b8, update to version 2.2.0b8 or later.
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Checkmk