CVE-2023-6156: Livestatus injection in availability timeline
Improper neutralization of livestatus command delimiters in the availability timeline in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbitrary livestatus command execution for authorized users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6156?
CVE-2023-6156 has a medium severity level due to its potential for arbitrary command execution.
How do I fix CVE-2023-6156?
To fix CVE-2023-6156, upgrade Checkmk to version 2.0.0p40 or later, 2.1.0p38 or later, or 2.2.0p16 or later.
Who is affected by CVE-2023-6156?
CVE-2023-6156 affects authorized users of Checkmk versions 2.0.0p39, 2.1.0p37, and 2.2.0p15 and earlier.
What is the impact of CVE-2023-6156?
The impact of CVE-2023-6156 allows authorized users to execute arbitrary livestatus commands, potentially compromising system integrity.
Is there a workaround for CVE-2023-6156?
Currently, there are no official workarounds for CVE-2023-6156 other than upgrading to a patched version.