Lucene search

K
nvd[email protected]NVD:CVE-2023-31210
HistoryDec 13, 2023 - 9:15 a.m.

CVE-2023-31210

2023-12-1309:15:34
CWE-427
web.nvd.nist.gov
1
checkmk
ld_library_path
user controlled
escalation
injection
security vulnerability

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

9.0%

Usage of user controlled LD_LIBRARY_PATH in agent in Checkmk 2.2.0p10 up to 2.2.0p16 allows malicious Checkmk site user to escalate rights via injection of malicious libraries

Affected configurations

Nvd
Node
checkmkcheckmkMatch2.2.0p10
OR
checkmkcheckmkMatch2.2.0p11
OR
checkmkcheckmkMatch2.2.0p12
OR
checkmkcheckmkMatch2.2.0p13
OR
checkmkcheckmkMatch2.2.0p14
OR
checkmkcheckmkMatch2.2.0p15
OR
checkmkcheckmkMatch2.2.0p16
VendorProductVersionCPE
checkmkcheckmk2.2.0cpe:2.3:a:checkmk:checkmk:2.2.0:p10:*:*:*:*:*:*
checkmkcheckmk2.2.0cpe:2.3:a:checkmk:checkmk:2.2.0:p11:*:*:*:*:*:*
checkmkcheckmk2.2.0cpe:2.3:a:checkmk:checkmk:2.2.0:p12:*:*:*:*:*:*
checkmkcheckmk2.2.0cpe:2.3:a:checkmk:checkmk:2.2.0:p13:*:*:*:*:*:*
checkmkcheckmk2.2.0cpe:2.3:a:checkmk:checkmk:2.2.0:p14:*:*:*:*:*:*
checkmkcheckmk2.2.0cpe:2.3:a:checkmk:checkmk:2.2.0:p15:*:*:*:*:*:*
checkmkcheckmk2.2.0cpe:2.3:a:checkmk:checkmk:2.2.0:p16:*:*:*:*:*:*

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

9.0%

Related for NVD:CVE-2023-31210