← Back

Checkmk

checkmk

Vendor: Tribe29 • 14 CVEs

CVEs (14)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Checkmk
Tribe29
2Checkmk
Checkmk
Nov 21, 2024
Jan 12, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
2Checkmk
Tribe29
2Checkmk
Checkmk
Nov 21, 2024
Jan 12, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
2Checkmk
Tribe29
2Checkmk
Checkmk
Nov 21, 2024
Jan 12, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Insufficient authentication flow in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows attacker to use locked credentials
2Checkmk
Tribe29
2Checkmk
Checkmk
Nov 21, 2024
Aug 10, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper neutralization of active check command arguments in Checkmk < 2.1.0p32, < 2.0.0p38, < 2.2.0p4 leads to arbitrary command execution for authenticated users.
2Checkmk
Tribe29
2Checkmk
Checkmk
Nov 21, 2024
May 17, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Improper Authorization in RestAPI in Checkmk GmbH's Checkmk versions <2.1.0p28 and <2.2.0b8 allows remote authenticated users to read arbitrary host_configs.
2Checkmk
Tribe29
2Checkmk
Checkmk
Nov 21, 2024
May 17, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for authorized users.
1Tribe29
1Checkmk
Nov 21, 2024
Apr 18, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Privilege escalation in Tribe29 Checkmk Appliance before 1.6.4 allows authenticated site users to escalate privileges via incorrectly set permissions.
2Checkmk
Tribe29
2Checkmk
Checkmk
Nov 21, 2024
Apr 4, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Inappropriate error handling in Tribe29 Checkmk <= 2.1.0p25, <= 2.0.0p34, <= 2.2.0b3 (beta), and all versions of Checkmk 1.6.0 causes the symmetric encryption of agent data to fail silently and transmit the data in plain...Show more
Inappropriate error handling in Tribe29 Checkmk <= 2.1.0p25, <= 2.0.0p34, <= 2.2.0b3 (beta), and all versions of Checkmk 1.6.0 causes the symmetric encryption of agent data to fail silently and transmit the data in plaintext in certain configurations.Show less
2Checkmk
Tribe29
2Checkmk
Checkmk
Nov 21, 2024
Mar 20, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
HTML Email Injection in Tribe29 Checkmk <=2.1.0p23; <=2.0.0p34, and all versions of Checkmk 1.6.0 allows an authenticated attacker to inject malicious HTML into Emails
2Checkmk
Tribe29
2Checkmk
Checkmk
Nov 21, 2024
Jan 26, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDAP user IDs to manipulate files on the server. Checkmk <= 2.1.0p19, Checkmk <= 2.0.0p32, and all versions of Checkmk 1.6.0...Show more
Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDAP user IDs to manipulate files on the server. Checkmk <= 2.1.0p19, Checkmk <= 2.0.0p32, and all versions of Checkmk 1.6.0 (EOL) are affected.Show less
2Checkmk
Tribe29
2Checkmk
Checkmk
Nov 21, 2024
Jun 17, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A permission issue affects users that deployed the shipped version of the Checkmk Debian package. Packages created by the agent bakery (enterprise editions only) were not affected. Using the shipped version of the agents...Show more
A permission issue affects users that deployed the shipped version of the Checkmk Debian package. Packages created by the agent bakery (enterprise editions only) were not affected. Using the shipped version of the agents, the maintainer scripts located at /var/lib/dpkg/info/ will be owned by the user and the group with ID 1001. If such a user exists on the system, they can change the content of these files (which are then executed by root). This leads to a local privilege escalation on the monitored host. Version 1.6 through 1.6.9p29, version 2.0 through 2.0.0p26, version 2.1 through 2.1.0p3, and version 2.2.0i1 are affected.Show less
2Checkmk
Tribe29
2Checkmk
Checkmk
Nov 21, 2024
May 20, 2022
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
In Checkmk before 1.6.0p29, 2.x before 2.0.0p25, and 2.1.x before 2.1.0b10, a site user can escalate to root by editing an OMD hook symlink.
2Checkmk
Tribe29
2Checkmk
Checkmk
Nov 21, 2024
Mar 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a backdoor on the device wit...Show more
CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a backdoor on the device with HTML content and interpreted by the browser (such as JavaScript or other client-side scripts) or to steal the session cookies of a user who has previously authenticated via a man in the middle. Successful exploitation requires access to the web service resource without authentication.Show less
2Checkmk
Tribe29
2Checkmk
Checkmk
Nov 21, 2024
Mar 25, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which are Extension Packages, making remote code execution possible. Successf...Show more
The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which are Extension Packages, making remote code execution possible. Successful exploitation requires access to the web management interface, either with valid credentials or with a hijacked session of a user with administrator role. NOTE: the vendor states that this is the intended behavior: admins are supposed to be able to execute code in this mannerShow less