Home
MEDIUM: 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:NDefault status
unaffected
2.4.0 (semver) before 2.4.0p16
affected
2.3.0 (semver)
affected
2.2.0 (semver)
affected
Description
Insufficient permission validation on multiple REST API endpoints in Checkmk 2.2.0, 2.3.0, and 2.4.0 before version 2.4.0p16 allows low-privileged users to perform unauthorized actions or obtain sensitive information
Problem types
CWE-280: Improper Handling of Insufficient Permissions or Privileges
Product status
2.4.0 (semver) before 2.4.0p16
2.3.0 (semver)
2.2.0 (semver)
Credits
PS Positive Security GmbH