Home
MEDIUM: 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NDefault status
unaffected
2.3.0 (semver) before 2.3.0p10
affected
2.2.0 (semver) before 2.2.0p31
affected
2.1.0 (semver) before 2.1.0p46
affected
2.0.0 (semver)
affected
Description
Certain http endpoints of Checkmk in Checkmk < 2.3.0p10 < 2.2.0p31, < 2.1.0p46, <= 2.0.0p39 allows remote attacker to bypass authentication and access data
Problem types
CWE-290: Authentication Bypass by Spoofing
Product status
2.3.0 (semver) before 2.3.0p10
2.2.0 (semver) before 2.2.0p31
2.1.0 (semver) before 2.1.0p46
2.0.0 (semver)
Credits
PS Positive Security GmbH