Lucene search

K
osvGoogleOSV:CVE-2022-47909
HistoryFeb 20, 2023 - 5:15 p.m.

CVE-2022-47909

2023-02-2017:15:12
Google
osv.dev
10
cve-2022-47909
lql injection
authuser http query
tribe29
checkmk 2.1.0p11
checkmk 2.0.0p28
checkmk 1.6.0 (eol)
localhost.

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

18.5%

Livestatus Query Language (LQL) injection in the AuthUser HTTP query header ofΒ Tribe29’s Checkmk <= 2.1.0p11, Checkmk <= 2.0.0p28, and all versions of Checkmk 1.6.0 (EOL) allows an attacker to perform direct queries to the application’s core from localhost.

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

18.5%