NA

CVE-2022-47909

Published: 20/02/2023 Updated: 21/12/2023
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

Livestatus Query Language (LQL) injection in the AuthUser HTTP query header of Tribe29's Checkmk <= 2.1.0p11, Checkmk <= 2.0.0p28, and all versions of Checkmk 1.6.0 (EOL) allows an malicious user to perform direct queries to the application's core from localhost.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tribe29 checkmk 2.1.0

tribe29 checkmk 2.0.0

tribe29 checkmk 1.6.0

Github Repositories

Unauthenticated Arbitrary File Deletion by abusing Livestatus Query Language Injection in Checkmk <= 2.1.0p11, Checkmk <= 2.0.0p28, and all versions of Checkmk 1.6.0 (EOL)

CVE-2022-47909 - Unauthenticated Arbitrary File Deletion This exploit abuses two CVEs in Checkmk &lt;= 210p11, Checkmk &lt;= 200p28, and all versions of Checkmk 160 (EOL) to achieve unauthenticated arbitrary file deletion CVE-2022-48321 - An SSRF vulnerability in the Agent_Receiver endpoint of the CheckMK software By abusing the vulnerable /register_with_hostna