CVE-2024-3367: Argument injection to runmqsc
Published Apr 16, 2024
·Updated
Argument injection in webspheremq agent plugin in Checkmk 2.0.0, 2.1.0, <2.2.0p26 and <2.3.0b5 allows local attacker to inject one argument to runmqsc
Affected Software
41 affected components
CheckMK Checkmk<=2.0.0
CheckMK Checkmk=2.1.0
CheckMK Checkmk=2.2.0
CheckMK Checkmk=2.2.0-b1
CheckMK Checkmk=2.2.0-b2
CheckMK Checkmk=2.2.0-b3
CheckMK Checkmk=2.2.0-b4
CheckMK Checkmk=2.2.0-b5
CheckMK Checkmk=2.2.0-b6
CheckMK Checkmk=2.2.0-b7
CheckMK Checkmk=2.2.0-b8
CheckMK Checkmk=2.2.0-i1
CheckMK Checkmk=2.2.0-p1
CheckMK Checkmk=2.2.0-p10
CheckMK Checkmk=2.2.0-p11
CheckMK Checkmk=2.2.0-p12
CheckMK Checkmk=2.2.0-p13
CheckMK Checkmk=2.2.0-p14
CheckMK Checkmk=2.2.0-p15
CheckMK Checkmk=2.2.0-p16
CheckMK Checkmk=2.2.0-p17
CheckMK Checkmk=2.2.0-p18
CheckMK Checkmk=2.2.0-p19
CheckMK Checkmk=2.2.0-p2
CheckMK Checkmk=2.2.0-p20
CheckMK Checkmk=2.2.0-p21
CheckMK Checkmk=2.2.0-p22
CheckMK Checkmk=2.2.0-p23
CheckMK Checkmk=2.2.0-p24
CheckMK Checkmk=2.2.0-p25
CheckMK Checkmk=2.2.0-p3
CheckMK Checkmk=2.2.0-p4
CheckMK Checkmk=2.2.0-p5
CheckMK Checkmk=2.2.0-p6
CheckMK Checkmk=2.2.0-p7
CheckMK Checkmk=2.2.0-p8
CheckMK Checkmk=2.2.0-p9
CheckMK Checkmk=2.3.0-b1
CheckMK Checkmk=2.3.0-b2
CheckMK Checkmk=2.3.0-b3
CheckMK Checkmk=2.3.0-b4
Event History
Apr 16, 2024
CVE Published
via MITRE·11:59 AM
Data Sourced
via MITRE·11:59 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-3367?
CVE-2024-3367 is considered a medium severity vulnerability due to argument injection that can be exploited by local attackers.
2
How do I fix CVE-2024-3367?
To fix CVE-2024-3367, update Checkmk to version 2.2.0p26 or later, or to version 2.3.0b5 or later.
3
What are the affected versions of Checkmk for CVE-2024-3367?
Affected versions of Checkmk for CVE-2024-3367 include versions 2.0.0 up to 2.1.0 and any versions below 2.2.0p26 and 2.3.0b5.
4
Can CVE-2024-3367 be exploited remotely?
No, CVE-2024-3367 requires local access to exploit the argument injection vulnerability.
5
What type of vulnerability is CVE-2024-3367 classified as?
CVE-2024-3367 is classified as an argument injection vulnerability in the websphere_mq agent plugin of Checkmk.