Werk #17987: Fix Livestatus injection in autocomplete endpoint
Component | REST API | ||||||||
Title | Fix Livestatus injection in autocomplete endpoint | ||||||||
Date | Jun 2, 2025 | ||||||||
Level | Trivial Change | ||||||||
Class | Security Fix | ||||||||
Compatibility | Compatible - no manual interaction needed | ||||||||
Checkmk versions & editions |
|
Before this fix, the autocomplete endpoint did not properly validate its parameters, allowing a malicious, authenticated user to inject livestatus
commands via the input.
This vulnerability was identified in a commissioned penetration test conducted by PS Positive Security GmbH.
Who's Affected:
This issue affects the REST API in all editions of Checkmk.
Affected Versions:
- 2.4.0
- 2.3.0
- 2.2.0
- 2.1.0 (EOL)
Vulnerability Management:
We have rated the issue with a CVSS score of 5.3 (Medium) with the following CVSS vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
, and assigned CVE-2025-32918
.