Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2wv3-wwxg-29gh

Опубликовано: 09 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3

Описание

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p21, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows users with the "Use WATO" permission to access the "Analyze configuration" page by directly navigating to its URL, bypassing the intended "Access analyze configuration" permission check. If these users also have the "Make changes, perform actions" permission, they can perform unauthorized actions such as disabling checks or acknowledging results.

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p21, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows users with the "Use WATO" permission to access the "Analyze configuration" page by directly navigating to its URL, bypassing the intended "Access analyze configuration" permission check. If these users also have the "Make changes, perform actions" permission, they can perform unauthorized actions such as disabling checks or acknowledging results.

EPSS

Процентиль: 15%
0.0005
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-862

Связанные уязвимости

ubuntu
около 2 месяцев назад

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p21, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows users with the "Use WATO" permission to access the "Analyze configuration" page by directly navigating to its URL, bypassing the intended "Access analyze configuration" permission check. If these users also have the "Make changes, perform actions" permission, they can perform unauthorized actions such as disabling checks or acknowledging results.

nvd
около 2 месяцев назад

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p21, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows users with the "Use WATO" permission to access the "Analyze configuration" page by directly navigating to its URL, bypassing the intended "Access analyze configuration" permission check. If these users also have the "Make changes, perform actions" permission, they can perform unauthorized actions such as disabling checks or acknowledging results.

debian
около 2 месяцев назад

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0 ...

EPSS

Процентиль: 15%
0.0005
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-862