Command injection via active checks and REST API
CVE-2023-31209
8.8HIGH
What is CVE-2023-31209?
The vulnerability in Checkmk, affecting versions prior to 2.1.0p32, 2.0.0p38, and 2.2.0p4, allows authenticated users to execute arbitrary commands due to improper handling of active check command arguments. This flaw poses a significant risk to the security of systems using Checkmk, enabling malicious users to compromise the integrity of the system.
Affected Version(s)
Checkmk 2.2.0 < 2.2.0p4
Checkmk 2.1.0 < 2.1.0p32
Checkmk 2.0.0 < 2.0.0p38
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved