Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Livestatus command injection in RestAPI
Vulnerability Description
Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0p39, 2.3.0p25, and 2.1.0p51 (EOL) allows arbitrary livestatus command execution. Exploitation requires the attacker to have a contact group assigned to their user account and for an event to originate from a host with the same contact group or from an event generated with an unknown host.
CVSS Information
N/A
Vulnerability Type
分隔符转义处理不恰当
Vulnerability Title
Checkmk 安全漏洞
Vulnerability Description
Checkmk是Checkmk公司的一个 IT 监控平台。 Checkmk存在安全漏洞,该漏洞源于livestatus命令分隔符中和不当,可能导致任意命令执行。以下版本受到影响:2.2.0p39之前版本、2.3.0p25之前版本和2.1.0p51之前版本。
CVSS Information
N/A
Vulnerability Type
N/A