Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2h2q-3qrx-m3j7

Опубликовано: 04 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 8.8

Описание

Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an authenticated user to inject arbitrary Livestatus commands.

Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an authenticated user to inject arbitrary Livestatus commands.

EPSS

Процентиль: 22%
0.00072
Низкий

5.3 Medium

CVSS4

8.8 High

CVSS3

Дефекты

CWE-140

Связанные уязвимости

CVSS3: 8.8
ubuntu
7 месяцев назад

Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an authenticated user to inject arbitrary Livestatus commands.

CVSS3: 8.8
nvd
7 месяцев назад

Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an authenticated user to inject arbitrary Livestatus commands.

CVSS3: 8.8
debian
7 месяцев назад

Improper neutralization of Livestatus command delimiters in autocomple ...

EPSS

Процентиль: 22%
0.00072
Низкий

5.3 Medium

CVSS4

8.8 High

CVSS3

Дефекты

CWE-140