CVE-2023-0284: Improper validation of LDAP user IDs
Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDAP user IDs to manipulate files on the server. Checkmk <= 2.1.0p19, Checkmk <= 2.0.0p32, and all versions of Checkmk 1.6.0 (EOL) are affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0284?
CVE-2023-0284 has a critical severity due to improper input validation that allows remote file manipulation.
How do I fix CVE-2023-0284?
To fix CVE-2023-0284, upgrade to Checkmk version 2.1.0p20 or later, or apply the relevant patches if available.
Which versions are affected by CVE-2023-0284?
CVE-2023-0284 affects Checkmk versions up to 2.1.0p19, 2.0.0p32, and all versions in the EOL 1.6.0 series.
What is the impact of CVE-2023-0284?
CVE-2023-0284 allows attackers to control LDAP user IDs and manipulate files on the server, compromising system integrity.
How can I verify if my Checkmk installation is vulnerable to CVE-2023-0284?
You can verify vulnerability by checking your Checkmk version against the affected versions listed in CVE-2023-0284.