CVE-2023-22307: Site-Passwords in GET parameters
Published Apr 18, 2023
·Updated
Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.4 allows local attacker to retrieve passwords via reading log files.
Affected Software
1 affected component
Tribe29 Checkmk Appliance Firmware<1.6.4
Event History
Apr 18, 2023
CVE Published
via MITRE·06:57 PM
Data Sourced
via MITRE·06:57 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this sensitive data exposure?
The vulnerability ID for this sensitive data exposure is CVE-2023-22307.
2
What is the affected software version for this vulnerability?
The affected software version for this vulnerability is Checkmk Appliance Firmware before 1.6.4.
3
What is the severity rating of this vulnerability?
The severity rating of this vulnerability is medium, with a score of 5.5.
4
How can a local attacker exploit this vulnerability?
A local attacker can exploit this vulnerability by reading log files to retrieve passwords.
5
Is there a fix or patch available for this vulnerability?
Yes, a fix is available for this vulnerability in Checkmk Appliance Firmware version 1.6.4.