CVE-2022-47909 MEDIUM

CVE-2022-47909: LQL Injection in Livestatus HTTP headers

Vendor Tribe29
Product Checkmk
Weakness CWE-20 · Input validation
Published February 20, 2023
Last update August 3, 2024

CVSS base score

6.8/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

Livestatus Query Language (LQL) injection in the AuthUser HTTP query header of Tribe29's Checkmk <= 2.1.0p11, Checkmk <= 2.0.0p28, and all versions of Checkmk 1.6.0 (EOL) allows an attacker to perform direct queries to the application's core from localhost.

Key dates

02Disclosure timeline

February 20, 2023 CVE published
August 3, 2024 Record updated