Catch up on the latest product updates, best practices, and expert insights from the Checkmk Conference #12 – Watch the livestream recordings now

Werk #16221: Livestatus Injections

Component Setup
Title Livestatus Injections
Date Nov 15, 2023
Level Trivial Change
Class Security Fix
Compatibility Compatible - no manual interaction needed
Checkmk versions & editions
2.3.0b1 Checkmk Community, Checkmk Pro, Checkmk Ultimate, Checkmk Ultimate MT
2.2.0p15 Checkmk Community, Checkmk Pro, Checkmk Ultimate, Checkmk Ultimate MT
2.1.0p37 Checkmk Community, Checkmk Pro, Checkmk Ultimate MT

Prior to this Werk it was possible to inject arbitrary livestatus commands to the core via the WebUI.

We found this vulnerability internally.

Affected Versions: * 2.2.0 * 2.1.0 * 2.0.0

Vulnerability Management: We have rated the issue with a CVSS Score of 7.6 (High) with the following CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H. We assigned CVE-2023-6156 and CVE-2023-6157 to these vulnerabilities.

Changes: This Werk strips the relevant parameters of newlines.

To the list of all Werks