Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-47909
HistoryFeb 20, 2023 - 12:00 a.m.

CVE-2022-47909

2023-02-2000:00:00
ubuntu.com
ubuntu.com
12
cve-2022-47909
lql injection
tribe29's checkmk
checkmk 1.6.0
localhost
unix
application core
http header

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

18.5%

Livestatus Query Language (LQL) injection in the AuthUser HTTP query header
of Tribe29’s Checkmk <= 2.1.0p11, Checkmk <= 2.0.0p28, and all versions of
Checkmk 1.6.0 (EOL) allows an attacker to perform direct queries to the
application’s core from localhost.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchcheck-mk< anyUNKNOWN
ubuntu16.04noarchcheck-mk< anyUNKNOWN

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

18.5%