CVE Vulnerabilities

CVE-2023-6287

Use of GET Request Method With Sensitive Query Strings

Published: Nov 27, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.8 allows local attacker to retrieve passwords via reading log files.

Weakness

The web application uses the HTTP GET method to process a request and includes sensitive information in the query string of that request.

Affected Software

Name Vendor Start Version End Version
Checkmk_appliance_firmware Tribe29 * 1.6.8 (excluding)
Check-mk Ubuntu bionic *
Check-mk Ubuntu trusty *
Check-mk Ubuntu xenial *

Potential Mitigations

References