Home
MEDIUM: 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:NDefault status
unaffected
2.5.0b1 (semver) before 2.5.0b2
affected
2.4.0 (semver) before 2.4.0p25
affected
Description
Insufficient permission validation on multiple REST API Quick Setup endpoints in Checkmk 2.5.0 (beta) before version 2.5.0b2 and 2.4.0 before version 2.4.0p25 allows low-privileged users to perform unauthorized actions or obtain sensitive information
Problem types
CWE-280: Improper Handling of Insufficient Permissions or Privileges
Product status
2.5.0b1 (semver) before 2.5.0b2
2.4.0 (semver) before 2.4.0p25
Credits
PS Positive Security GmbH