Impact
The vulnerability is caused by an improper handling of newline characters in the filter values used by the host and service list APIs of Checkmk. This flaw allows an authenticated user to inject additional Livestatus query headers, which can bypass the built‑in visibility restrictions on count queries and reveal information about hosts and services that lie outside the attacker’s contact groups. The injected headers may also cause resource exhaustion on the web server and Livestatus workers for a duration controlled by the attacker, potentially impacting the availability of the monitoring system.
Affected Systems
Checkmk products prior to version 2.5.0p14 are affected. The issue applies to any Checkmk deployment that enables the monitoring host or service list APIs and allows authenticated users to specify filter values.
Risk and Exploitability
The CVSS score for this vulnerability is 5.3, indicating a moderate risk level. Exploit probability is not quantified in the EPSS data, and the vulnerability is not listed in CISA’s KEV catalog. Because the flaw requires authentication and relies on a legitimate user’s ability to submit filter values, the likely attack vector is an internal or compromised user with sufficient privileges. If an attacker can exploit the injection, they may gain unauthorized visibility into the monitoring data and, by saturating the Livestatus workers, potentially degrade the availability of the monitoring infrastructure.
OpenCVE Enrichment