Remote Code Execution Vulnerability in Tribe29's Checkmk

Remote Code Execution Vulnerability in Tribe29's Checkmk

CVE-2022-46302 · HIGH Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Broad access controls could allow site users to directly interact with the system Apache installation when providing the reverse proxy configurations for Tribe29's Checkmk <= 2.1.0p6, Checkmk <= 2.0.0p27, and all versions of Checkmk 1.6.0 (EOL) allowing an attacker to perform remote code execution with root privileges on the underlying host.

Learn more about our Cis Benchmark Audit For Apache Http Server.