CVE-2022-46302: Remote Code Execution with Root Privileges via Broad Apache Permissions
Broad access controls could allow site users to directly interact with the system Apache installation when providing the reverse proxy configurations for Tribe29's Checkmk <= 2.1.0p6, Checkmk <= 2.0.0p27, and all versions of Checkmk 1.6.0 (EOL) allowing an attacker to perform remote code execution with root privileges on the underlying host.
Affected Software
Event History
Frequently Asked Questions
What are the affected versions for CVE-2022-46302?
CVE-2022-46302 affects Tribe29's Checkmk versions 1.6.0, 2.0.0, and up to 2.1.0p6.
What is the impact of CVE-2022-46302?
CVE-2022-46302 could allow unauthorized site users to interact directly with the system's Apache installation.
How can I mitigate CVE-2022-46302?
To mitigate CVE-2022-46302, ensure that you apply the latest security patches provided by Tribe29 for affected Checkmk versions.
What kind of access is granted by exploiting CVE-2022-46302?
Exploiting CVE-2022-46302 may allow an attacker to perform remote code execution on the Checkmk server.
Is CVE-2022-46302 considered critical?
CVE-2022-46302 is classified as a high-severity vulnerability due to the potential for unauthorized access and remote execution.