CVE-2024-38865

Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0p39, 2.3.0p25, and 2.1.0p51 (EOL) allows arbitrary livestatus command execution. Exploitation requires the attacker to have a contact group assigned to their user account and for an event to originate from a host with the same contact group or from an event generated with an unknown host.
CVSS

No CVSS.

References
Configurations

No configuration.

History

11 Apr 2025, 15:39

Type Values Removed Values Added
Summary
  • (es) La neutralización incorrecta de los delimitadores del comando livestatus en un endpoint específico dentro de RestAPI de Checkmk anterior a 2.2.0p39, 2.3.0p25 y 2.1.0p51 (EOL) permite la ejecución arbitraria del comando livestatus. La explotación requiere que el atacante tenga un grupo de contactos asignado a su cuenta de usuario y que un evento se origine desde un host con el mismo grupo de contactos o desde un evento generado con un host desconocido.

10 Apr 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-10 08:15

Updated : 2025-04-11 15:39


NVD link : CVE-2024-38865

Mitre link : CVE-2024-38865

CVE.ORG link : CVE-2024-38865


JSON object : View

Products Affected

No product.

CWE
CWE-140

Improper Neutralization of Delimiters