2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2023-2020" ,
"sourceIdentifier" : "security@checkmk.com" ,
"published" : "2023-04-18T12:15:07.537" ,
2023-04-27 22:00:28 +02:00
"lastModified" : "2023-04-27T19:48:47.017" ,
"vulnStatus" : "Analyzed" ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Insufficient permission checks in the REST API in Tribe29 Checkmk <= 2.1.0p27 and <= 2.2.0b4 (beta) allow unauthorized users to schedule downtimes for any host."
}
] ,
"metrics" : {
"cvssMetricV31" : [
2023-04-27 22:00:28 +02:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "LOW" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 4.3 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 1.4
} ,
2023-04-24 12:24:31 +02:00
{
"source" : "security@checkmk.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "LOW" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 4.3 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 1.4
}
]
} ,
"weaknesses" : [
2023-04-27 22:00:28 +02:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-863"
}
]
} ,
2023-04-24 12:24:31 +02:00
{
"source" : "security@checkmk.com" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-280"
}
]
}
] ,
2023-04-27 22:00:28 +02:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:-:*:*:*:*:*:*" ,
"matchCriteriaId" : "BC0AC5A2-3724-4942-ABE2-CA9F3B9B4BDA"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:b1:*:*:*:*:*:*" ,
"matchCriteriaId" : "E3AAC1AD-C2F5-4171-BD92-95A8BA09E79A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:b2:*:*:*:*:*:*" ,
"matchCriteriaId" : "8CB8C4BB-4AE6-4EA2-8F38-780B627721ED"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:b3:*:*:*:*:*:*" ,
"matchCriteriaId" : "D0F14106-2A3D-4FC7-A0C7-6EDA75D1A8F7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:b4:*:*:*:*:*:*" ,
"matchCriteriaId" : "F8C2DA36-8419-4846-BFA0-A729BE7D72C5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:b5:*:*:*:*:*:*" ,
"matchCriteriaId" : "8AA4FA3D-7A59-4597-9D79-B6B020D86BD1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:b6:*:*:*:*:*:*" ,
"matchCriteriaId" : "79F0CF88-FF11-4741-AFF6-9F88F57C2140"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:b7:*:*:*:*:*:*" ,
"matchCriteriaId" : "8E93629E-C0CB-4636-B343-1C0646D8228E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:b8:*:*:*:*:*:*" ,
"matchCriteriaId" : "58102464-E66F-49CD-8952-3F3F9A6A45CC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:b9:*:*:*:*:*:*" ,
"matchCriteriaId" : "9C98E509-8466-4F95-ABE7-7ECC91640E04"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:p1:*:*:*:*:*:*" ,
"matchCriteriaId" : "A7B89F71-ABD2-4B2D-AE6B-C0F243E89443"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:p10:*:*:*:*:*:*" ,
"matchCriteriaId" : "002EF417-C702-42E2-9C8F-C9593B43AB03"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:p11:*:*:*:*:*:*" ,
"matchCriteriaId" : "B8E358A9-0430-4EF1-8557-7F1C088FFF48"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:p12:*:*:*:*:*:*" ,
"matchCriteriaId" : "4B0AF395-FDC7-4321-9E00-C935641C138B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:p13:*:*:*:*:*:*" ,
"matchCriteriaId" : "59B9CCED-806F-47EF-B5B6-441AADCB4B81"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:p14:*:*:*:*:*:*" ,
"matchCriteriaId" : "FAED2CD5-A2CE-438C-8ED7-338D9D61FBD9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:p15:*:*:*:*:*:*" ,
"matchCriteriaId" : "F08A96EF-FD2E-4D45-884B-349869649C3D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:p16:*:*:*:*:*:*" ,
"matchCriteriaId" : "E80D718E-66B6-4FC6-911D-C264F2C891C9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:p17:*:*:*:*:*:*" ,
"matchCriteriaId" : "174BF76A-00C5-4ECD-937D-FE66851D3979"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:p18:*:*:*:*:*:*" ,
"matchCriteriaId" : "F43DBAE4-FEF9-431E-AE82-31C7944CA830"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:p2:*:*:*:*:*:*" ,
"matchCriteriaId" : "960DF373-EDE6-4318-B6E9-07573ED5907A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:p20:*:*:*:*:*:*" ,
"matchCriteriaId" : "5FFBF793-48E0-48DB-9C12-1C4A5805009E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:p21:*:*:*:*:*:*" ,
"matchCriteriaId" : "B6A2F0DB-CA73-4F14-8099-7A29BADC1F4E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:p22:*:*:*:*:*:*" ,
"matchCriteriaId" : "5D23ECB8-9C2C-4BA5-ADD6-248FD2CFF37A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:p23:*:*:*:*:*:*" ,
"matchCriteriaId" : "9958D126-EF50-4ED7-85A3-6E5120EFB931"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:p24:*:*:*:*:*:*" ,
"matchCriteriaId" : "5D9B3F5F-158A-4C43-A894-1A55D1D758FC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:p25:*:*:*:*:*:*" ,
"matchCriteriaId" : "17729C6D-3DD1-4082-B3AF-B53770304F7B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:p26:*:*:*:*:*:*" ,
"matchCriteriaId" : "2E34014C-90A0-4ABB-A15F-73E83F312246"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:p27:*:*:*:*:*:*" ,
"matchCriteriaId" : "C0DCB95E-CC14-40BF-A7E4-1CD9075E2785"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:p3:*:*:*:*:*:*" ,
"matchCriteriaId" : "3144AABF-74CB-44EE-A618-8529A8ACFCF6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:p4:*:*:*:*:*:*" ,
"matchCriteriaId" : "88AC7AB0-40DF-44D1-83EA-FDD4D5346BBD"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:p5:*:*:*:*:*:*" ,
"matchCriteriaId" : "4285A4A3-3DED-456D-93D4-1B9FDB42C1EB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:p6:*:*:*:*:*:*" ,
"matchCriteriaId" : "098FD286-B6CB-4428-9A62-A5F24B4D9E92"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:p7:*:*:*:*:*:*" ,
"matchCriteriaId" : "8400088B-E56E-4D0B-86D5-76D884C8031A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:p8:*:*:*:*:*:*" ,
"matchCriteriaId" : "29554684-FEFF-42B2-B62E-6523782F537C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.1.0:p9:*:*:*:*:*:*" ,
"matchCriteriaId" : "91AE66E4-AE6B-4F25-9312-6418FC3E221F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.2.0:b1:*:*:*:*:*:*" ,
"matchCriteriaId" : "A954DDB4-ACF5-4D74-B735-0BB14762457C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.2.0:b2:*:*:*:*:*:*" ,
"matchCriteriaId" : "F4E9D8E0-ECFF-4987-8189-F6A5917D39B6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.2.0:b3:*:*:*:*:*:*" ,
"matchCriteriaId" : "7CDF16A7-E9BC-488B-A0DF-91B7F79C2D7A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.2.0:b4:*:*:*:*:*:*" ,
"matchCriteriaId" : "EF3C4AB5-966A-46CD-8774-7BD4115FC80B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.2.0:i1:*:*:*:*:*:*" ,
"matchCriteriaId" : "AB444D23-88E8-4AFE-9F1E-56AE4ADF7644"
}
]
}
]
}
] ,
2023-04-24 12:24:31 +02:00
"references" : [
{
"url" : "https://checkmk.com/werk/13981" ,
2023-04-27 22:00:28 +02:00
"source" : "security@checkmk.com" ,
"tags" : [
"Vendor Advisory"
]
2023-04-24 12:24:31 +02:00
}
]
}