CVE Vulnerabilities

CVE-2023-6287

Use of GET Request Method With Sensitive Query Strings

Published: Nov 27, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.8 allows local attacker to retrieve passwords via reading log files.

Weakness

The web application uses the HTTP GET method to process a request and includes sensitive information in the query string of that request.

Affected Software

NameVendorStart VersionEnd Version
Checkmk_appliance_firmwareTribe29*1.6.8 (excluding)
Check-mkUbuntubionic*
Check-mkUbuntutrusty*
Check-mkUbuntuxenial*

Potential Mitigations

References