Vulnerability Description
Broad access controls could allow site users to directly interact with the system Apache installation when providing the reverse proxy configurations for Tribe29's Checkmk <= 2.1.0p6, Checkmk <= 2.0.0p27, and all versions of Checkmk 1.6.0 (EOL) allowing an attacker to perform remote code execution with root privileges on the underlying host.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Checkmk | Checkmk | 1.6.0 |
Related Weaknesses (CWE)
References
- https://checkmk.com/werk/14281MitigationVendor Advisory
- https://checkmk.com/werk/14281MitigationVendor Advisory
FAQ
What is CVE-2022-46302?
CVE-2022-46302 is a vulnerability with a CVSS score of 8.8 (HIGH). Broad access controls could allow site users to directly interact with the system Apache installation when providing the reverse proxy configurations for Tribe29's Checkmk <= 2.1.0p6, Checkmk <= 2.0.0...
How severe is CVE-2022-46302?
CVE-2022-46302 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-46302?
Check the references section above for vendor advisories and patch information. Affected products include: Checkmk Checkmk.