CVE-2022-48321: SSRF in agent-receiver API
Limited Server-Side Request Forgery (SSRF) in agent-receiver in Tribe29's Checkmk <= 2.1.0p11 allows an attacker to communicate with local network restricted endpoints by use of the host registration API.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-48321?
CVE-2022-48321 is a vulnerability in Tribe29's Checkmk <= 2.1.0p11 that allows an attacker to communicate with local network restricted endpoints by using the host registration API.
What is the severity of CVE-2022-48321?
CVE-2022-48321 has a severity rating of 7.8, which is classified as high.
How does CVE-2022-48321 affect Tribe29 Checkmk?
CVE-2022-48321 affects Tribe29 Checkmk versions 2.1.0 to 2.1.0p11, including the beta versions.
How can an attacker exploit CVE-2022-48321?
An attacker can exploit CVE-2022-48321 by performing a limited Server-Side Request Forgery (SSRF) in the agent-receiver component of Tribe29 Checkmk, allowing them to communicate with restricted local network endpoints.
Is there a fix for CVE-2022-48321?
Yes, there is a fix available for CVE-2022-48321. Users should update to Checkmk version 2.1.0p12 or a later version to mitigate the vulnerability.