Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-34x2-m38g-824f

Опубликовано: 13 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 4.3

Описание

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows authenticated users to enumerate existing hosts by observing different HTTP response codes in agent-receiver/register_existing endpoint, which could lead to information disclosure.

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows authenticated users to enumerate existing hosts by observing different HTTP response codes in agent-receiver/register_existing endpoint, which could lead to information disclosure.

EPSS

Процентиль: 9%
0.00032
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-204

Связанные уязвимости

CVSS3: 4.3
ubuntu
20 дней назад

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows authenticated users to enumerate existing hosts by observing different HTTP response codes in agent-receiver/register_existing endpoint, which could lead to information disclosure.

CVSS3: 4.3
nvd
20 дней назад

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows authenticated users to enumerate existing hosts by observing different HTTP response codes in agent-receiver/register_existing endpoint, which could lead to information disclosure.

CVSS3: 4.3
debian
20 дней назад

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0 ...

EPSS

Процентиль: 9%
0.00032
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-204