VYPR
Unrated severityNVD Advisory· Published Apr 18, 2023· Updated Feb 5, 2025

Unauthorized scheduling of downtimes via REST API

CVE-2023-2020

Description

Insufficient permission checks in the REST API in Tribe29 Checkmk <= 2.1.0p27 and <= 2.2.0b4 (beta) allow unauthorized users to schedule downtimes for any host.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.