Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an authenticated user to inject arbitrary Livestatus commands.
References
History

Fri, 04 Jul 2025 08:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an authenticated user to inject arbitrary Livestatus commands.
Title Livestatus injection in autocomplete endpoint
Weaknesses CWE-140
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Checkmk

Published: 2025-07-04T08:12:21.950Z

Updated: 2025-07-04T08:12:21.950Z

Reserved: 2025-04-14T09:52:19.273Z

Link: CVE-2025-32918

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-07-04T08:15:25.520

Modified: 2025-07-04T08:15:25.520

Link: CVE-2025-32918

cve-icon Redhat

No data.