Логотип exploitDog
bind:CVE-2024-38865
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-38865

Количество 4

Количество 4

ubuntu логотип

CVE-2024-38865

10 месяцев назад

Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0p39, 2.3.0p25, and 2.1.0p51 (EOL) allows arbitrary livestatus command execution. Exploitation requires the attacker to have a contact group assigned to their user account and for an event to originate from a host with the same contact group or from an event generated with an unknown host.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2024-38865

10 месяцев назад

Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0p39, 2.3.0p25, and 2.1.0p51 (EOL) allows arbitrary livestatus command execution. Exploitation requires the attacker to have a contact group assigned to their user account and for an event to originate from a host with the same contact group or from an event generated with an unknown host.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2024-38865

10 месяцев назад

Improper neutralization of livestatus command delimiters in a specific ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-cc76-vj8r-jr9w

10 месяцев назад

Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0p39, 2.3.0p25, and 2.1.0p51 (EOL) allows arbitrary livestatus command execution. Exploitation requires the attacker to have a contact group assigned to their user account and for an event to originate from a host with the same contact group or from an event generated with an unknown host.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-38865

Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0p39, 2.3.0p25, and 2.1.0p51 (EOL) allows arbitrary livestatus command execution. Exploitation requires the attacker to have a contact group assigned to their user account and for an event to originate from a host with the same contact group or from an event generated with an unknown host.

CVSS3: 8.8
1%
Низкий
10 месяцев назад
nvd логотип
CVE-2024-38865

Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0p39, 2.3.0p25, and 2.1.0p51 (EOL) allows arbitrary livestatus command execution. Exploitation requires the attacker to have a contact group assigned to their user account and for an event to originate from a host with the same contact group or from an event generated with an unknown host.

CVSS3: 8.8
1%
Низкий
10 месяцев назад
debian логотип
CVE-2024-38865

Improper neutralization of livestatus command delimiters in a specific ...

CVSS3: 8.8
1%
Низкий
10 месяцев назад
github логотип
GHSA-cc76-vj8r-jr9w

Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0p39, 2.3.0p25, and 2.1.0p51 (EOL) allows arbitrary livestatus command execution. Exploitation requires the attacker to have a contact group assigned to their user account and for an event to originate from a host with the same contact group or from an event generated with an unknown host.

CVSS3: 8.8
1%
Низкий
10 месяцев назад

Уязвимостей на страницу