216.73.216.36

CVE-2024-38865

· Published 10/04/2025 08:15 · Modified 10/04/2025 08:15

Labels: CVE-2024-38865 2025-04-10CVE-2024-38865CWE-140[email protected]

Essential information

Published
10/04/2025 08:15
Modified
10/04/2025 08:15
Author
Creator
CVSS
6.0 MEDIUM (v3) 6.0 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0p39, 2.3.0p25, and 2.1.0p51 (EOL) allows arbitrary livestatus command execution. Exploitation requires the attacker to have a contact group assigned to their user account and for an event to originate from a host with the same contact group or from an event generated with an unknown host.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
checkmk / checkmk cpe:2.3:a:checkmk:checkmk:<2.2.0:p39:*:*:*:*:*:*:*
checkmk / checkmk cpe:2.3:a:checkmk:checkmk:2.2.0:p39:*:*:*:*:*:*:*
checkmk / checkmk cpe:2.3:a:checkmk:checkmk:2.3.0:p25:*:*:*:*:*:*:*
checkmk / checkmk cpe:2.3:a:checkmk:checkmk:2.1.0:p51:*:*:*:*:*:*:*

References