Security Advisory

CVE-2025-32918

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-07-04 08:12:21
Last updated 2025-07-08 14:20:25
Assigner Checkmk
CVSS score not scored
State PUBLISHED

Description

Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an authenticated user to inject arbitrary Livestatus commands.