Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cpgc-jhjc-98r4

Опубликовано: 17 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.3

Описание

Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for authorized users.

Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for authorized users.

EPSS

Процентиль: 66%
0.00513
Низкий

8.3 High

CVSS3

Дефекты

CWE-140
CWE-77

Связанные уязвимости

CVSS3: 8.3
ubuntu
больше 2 лет назад

Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for authorized users.

CVSS3: 8.3
nvd
больше 2 лет назад

Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for authorized users.

CVSS3: 8.3
debian
больше 2 лет назад

Improper neutralization of livestatus command delimiters in the RestAP ...

EPSS

Процентиль: 66%
0.00513
Низкий

8.3 High

CVSS3

Дефекты

CWE-140
CWE-77