CVE-2022-48321 MEDIUM

CVE-2022-48321: SSRF in agent-receiver API

Vendor Tribe29
Product Checkmk
Weakness CWE-20 · Input validation
Published February 20, 2023
Last update August 3, 2024

CVSS base score

6.8/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

Limited Server-Side Request Forgery (SSRF) in agent-receiver in Tribe29's Checkmk <= 2.1.0p11 allows an attacker to communicate with local network restricted endpoints by use of the host registration API.

Key dates

02Disclosure timeline

February 20, 2023 CVE published
August 3, 2024 Record updated