CVE-2023-0284
Published on: Not Yet Published
Last Modified on: 02/06/2023 04:46:00 PM UTC
Certain versions of Checkmk from Tribe29 contain the following vulnerability:
Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDAP user IDs to manipulate files on the server. Checkmk <= 2.1.0p19, Checkmk <= 2.0.0p32, and all versions of Checkmk 1.6.0 (EOL) are affected.
- CVE-2023-0284 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
Tribe29 - Checkmk version = 2.0.0
- Affected Vendor/Software:
Tribe29 - Checkmk version = 2.1.0
- Affected Vendor/Software:
Tribe29 - Checkmk version = 1.6.0
CVSS3 Score: 8.1 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Improper validation of LDAP user IDs | checkmk.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Tribe29 | Checkmk | All | All | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | - | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | b1 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | b2 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | b3 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | b4 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | b5 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | b6 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | b7 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | b8 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | i1 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p1 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p10 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p11 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p12 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p13 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p14 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p15 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p16 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p17 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p18 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p19 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p2 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p20 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p21 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p22 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p23 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p24 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p25 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p26 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p27 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p28 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p29 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p3 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p30 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p31 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p32 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p4 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p5 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p6 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p7 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p8 | All | All |
Application | Tribe29 | Checkmk | 2.0.0 | p9 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | b1 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | b2 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | b3 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | b4 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | b5 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | b6 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | b7 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | b8 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | b9 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | p1 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | p10 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | p11 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | p12 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | p13 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | p14 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | p15 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | p16 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | p17 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | p18 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | p19 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | p2 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | p3 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | p4 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | p5 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | p6 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | p7 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | p8 | All | All |
Application | Tribe29 | Checkmk | 2.1.0 | p9 | All | All |
- cpe:2.3:a:tribe29:checkmk:*:*:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:-:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:b1:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:b2:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:b3:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:b4:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:b5:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:b6:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:b7:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:b8:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:i1:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p1:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p10:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p11:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p12:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p13:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p14:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p15:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p16:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p17:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p18:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p19:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p2:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p20:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p21:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p22:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p23:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p24:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p25:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p26:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p27:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p28:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p29:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p3:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p30:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p31:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p32:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p4:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p5:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p6:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p7:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p8:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.0.0:p9:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:b1:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:b2:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:b3:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:b4:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:b5:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:b6:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:b7:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:b8:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:b9:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:p1:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:p10:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:p11:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:p12:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:p13:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:p14:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:p15:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:p16:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:p17:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:p18:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:p19:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:p2:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:p3:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:p4:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:p5:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:p6:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:p7:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:p8:*:*:*:*:*:*:
- cpe:2.3:a:tribe29:checkmk:2.1.0:p9:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-0284 : Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDA… twitter.com/i/web/status/1… | 2023-01-26 21:45:32 |