Bypass of two factor authentication in RestAPI in Checkmk < 2.3.0p16 and < 2.2.0p34 allows authenticated users to bypass two factor authentication
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Checkmk | Checkmk | 2.3.0 (including) | 2.3.0 (including) |
Checkmk | Checkmk | 2.3.0-p1 (including) | 2.3.0-p1 (including) |
Checkmk | Checkmk | 2.3.0-p10 (including) | 2.3.0-p10 (including) |
Checkmk | Checkmk | 2.3.0-p11 (including) | 2.3.0-p11 (including) |
Checkmk | Checkmk | 2.3.0-p12 (including) | 2.3.0-p12 (including) |
Checkmk | Checkmk | 2.3.0-p13 (including) | 2.3.0-p13 (including) |
Checkmk | Checkmk | 2.3.0-p14 (including) | 2.3.0-p14 (including) |
Checkmk | Checkmk | 2.3.0-p15 (including) | 2.3.0-p15 (including) |
Checkmk | Checkmk | 2.3.0-p2 (including) | 2.3.0-p2 (including) |
Checkmk | Checkmk | 2.3.0-p3 (including) | 2.3.0-p3 (including) |
Checkmk | Checkmk | 2.3.0-p4 (including) | 2.3.0-p4 (including) |
Checkmk | Checkmk | 2.3.0-p5 (including) | 2.3.0-p5 (including) |
Checkmk | Checkmk | 2.3.0-p6 (including) | 2.3.0-p6 (including) |
Checkmk | Checkmk | 2.3.0-p7 (including) | 2.3.0-p7 (including) |
Checkmk | Checkmk | 2.3.0-p8 (including) | 2.3.0-p8 (including) |
Checkmk | Checkmk | 2.3.0-p9 (including) | 2.3.0-p9 (including) |