Command injection in SMS notifications in Tribe29 Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker with User Management permissions, as well as LDAP administrators in certain scenarios, to perform arbitrary commands within the context of the application's local permissions.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-49120 | Command injection in SMS notifications in Tribe29 Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker with User Management permissions, as well as LDAP administrators in certain scenarios, to perform arbitrary commands within the context of the application's local permissions. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://checkmk.com/werk/14381 |
|
History
Wed, 12 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Tribe29
Published:
Updated: 2025-03-12T18:13:23.660Z
Reserved: 2023-01-18T15:49:58.122Z
Link: CVE-2022-46303
Updated: 2024-08-03T14:31:45.469Z
Status : Modified
Published: 2023-02-20T17:15:12.073
Modified: 2024-11-21T07:30:20.673
Link: CVE-2022-46303
No data.
OpenCVE Enrichment
No data.
EUVD