CVE-2014-2331: Code Injection
Published Aug 31, 2015
·Updated
CheckMK 1.2.2p2, 1.2.2p3, and 1.2.3i5 allows remote authenticated users to execute arbitrary Python code via a crafted rules.mk file in a snapshot. NOTE: this can be exploited by remote attackers by leveraging CVE-2014-2330.
Affected Software
2 affected components
Check Mk Project Check Mk<=1.2.2
Check Mk Project Check Mk<=1.2.3
Event History
Aug 31, 2015
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-2331?
CVE-2014-2331 is classified as a high severity vulnerability due to its potential for remote exploitation.
2
How do I fix CVE-2014-2331?
To fix CVE-2014-2331, you should upgrade to a later version of Check_MK that does not include this vulnerability.
3
Who is affected by CVE-2014-2331?
CVE-2014-2331 affects Check_MK versions 1.2.2p2, 1.2.2p3, and 1.2.3i5.
4
What can attackers do with CVE-2014-2331?
Attackers can execute arbitrary Python code on the server by exploiting CVE-2014-2331 through crafted rules.mk files.
5
Is CVE-2014-2331 related to any other vulnerabilities?
Yes, CVE-2014-2331 can be exploited in conjunction with CVE-2014-2330, allowing for further attack vectors.