Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-31207
HistoryMay 02, 2023 - 12:00 a.m.

CVE-2023-31207

2023-05-0200:00:00
ubuntu.com
ubuntu.com
17
transmission
credentials
query parameters
apache
access log
unix

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

9.0%

Transmission of credentials within query parameters in Checkmk <= 2.1.0p26,
<= 2.0.0p35, and <= 2.2.0b6 (beta) may cause the automation user’s secret
to be written to the site Apache access log.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchcheck-mk< anyUNKNOWN
ubuntu16.04noarchcheck-mk< anyUNKNOWN

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

9.0%

Related for UB:CVE-2023-31207