Security Advisory

CVE-2022-46302

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-04-20 13:06:30
Last updated 2025-02-04 21:43:19
Assigner Tribe29
CVSS score 8.8
State PUBLISHED

Description

Broad access controls could allow site users to directly interact with the system Apache installation when providing the reverse proxy configurations for Tribe29's Checkmk <= 2.1.0p6, Checkmk <= 2.0.0p27, and all versions of Checkmk 1.6.0 (EOL) allowing an attacker to perform remote code execution with root privileges on the underlying host.