CVE-2023-0284
Last modified
CVE-2023-0284 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDAP user IDs to manipulate files on the server. Checkmk <= 2.1.0p19, Checkmk <= 2.0.0p32, and all versions of Checkmk 1.6.0 (EOL) are affected.. EPSS estimates a 0.92% chance of exploitation in the next 30 days.
Description
Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDAP user IDs to manipulate files on the server. Checkmk <= 2.1.0p19, Checkmk <= 2.0.0p32, and all versions of Checkmk 1.6.0 (EOL) are affected.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Checkmk | Checkmk | 2.0.0 | — |
| Checkmk | Checkmk | 2.1.0 | B1 |
| Tribe29 | Checkmk | >= 1.6.0, < 2.0.0 | — |
References
- https://checkmk.com/werk/15181Vendor Advisory
- https://checkmk.com/werk/15181Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-0284?
How severe is CVE-2023-0284?
How do I fix CVE-2023-0284?
Are you affected by CVE-2023-0284?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
