CVE-2023-22294: Privilege escalation in Checkmk Appliance
Published Apr 18, 2023
·Updated
Privilege escalation in Tribe29 Checkmk Appliance before 1.6.4 allows authenticated site users to escalate privileges via incorrectly set permissions.
Affected Software
1 affected component
Tribe29 Checkmk<1.6.4
Event History
Apr 18, 2023
CVE Published
via MITRE·06:59 PM
Data Sourced
via MITRE·06:59 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this privilege escalation vulnerability?
The vulnerability ID for this privilege escalation vulnerability is CVE-2023-22294.
2
What is the severity of CVE-2023-22294?
The severity of CVE-2023-22294 is high with a CVSS score of 8.8.
3
What software is affected by CVE-2023-22294?
Tribe29 Checkmk Appliance before version 1.6.4 is affected by CVE-2023-22294.
4
How can authenticated site users exploit CVE-2023-22294?
Authenticated site users can exploit CVE-2023-22294 by escalating privileges via incorrectly set permissions.
5
Is there a patch available for CVE-2023-22294?
Yes, a patch for CVE-2023-22294 is available in Checkmk version 1.6.4 and later.