Command injection via active checks and REST API
CVE-2023-31209

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
10 August 2023

What is CVE-2023-31209?

The vulnerability in Checkmk, affecting versions prior to 2.1.0p32, 2.0.0p38, and 2.2.0p4, allows authenticated users to execute arbitrary commands due to improper handling of active check command arguments. This flaw poses a significant risk to the security of systems using Checkmk, enabling malicious users to compromise the integrity of the system.

Affected Version(s)

Checkmk 2.2.0 < 2.2.0p4

Checkmk 2.1.0 < 2.1.0p32

Checkmk 2.0.0 < 2.0.0p38

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.