{"id":"CVE-2022-48321","details":"Limited Server-Side Request Forgery (SSRF) in agent-receiver in Tribe29's Checkmk \u003c= 2.1.0p11 allows an attacker to communicate with local network restricted endpoints by use of the host registration API.","modified":"2026-07-09T05:18:01.272437Z","published":"2023-02-20T17:15:12.607Z","references":[{"type":"ADVISORY","url":"https://checkmk.com/werk/14385"},{"type":"EVIDENCE","url":"https://www.sonarsource.com/blog/checkmk-rce-chain-1/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/checkmk/checkmk","events":[{"introduced":"6a686961c4b760c55a13cfdb61e7c02be832a0be"},{"last_affected":"4be57271cbf081c9a1719dc3b1718b43d5e52f4b"}],"database_specific":{"cpe":["cpe:2.3:a:checkmk:checkmk:2.1.0:-:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.1.0:b1:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.1.0:p1:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.1.0:b2:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.1.0:p2:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.1.0:b3:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.1.0:p3:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.1.0:b4:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.1.0:p4:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.1.0:b5:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.1.0:p5:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.1.0:b6:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.1.0:p6:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.1.0:b7:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.1.0:p7:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.1.0:b8:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.1.0:p8:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.1.0:b9:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.1.0:p9:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.1.0:p10:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.1.0:p11:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2.1.0-NA"},{"last_affected":"2.1.0-NA"},{"introduced":"2.1.0-b1"},{"last_affected":"2.1.0-b1"},{"introduced":"2.1.0-p1"},{"last_affected":"2.1.0-p1"},{"introduced":"2.1.0-b2"},{"last_affected":"2.1.0-b2"},{"introduced":"2.1.0-p2"},{"last_affected":"2.1.0-p2"},{"introduced":"2.1.0-b3"},{"last_affected":"2.1.0-b3"},{"introduced":"2.1.0-p3"},{"last_affected":"2.1.0-p3"},{"introduced":"2.1.0-b4"},{"last_affected":"2.1.0-b4"},{"introduced":"2.1.0-p4"},{"last_affected":"2.1.0-p4"},{"introduced":"2.1.0-b5"},{"last_affected":"2.1.0-b5"},{"introduced":"2.1.0-p5"},{"last_affected":"2.1.0-p5"},{"introduced":"2.1.0-b6"},{"last_affected":"2.1.0-b6"},{"introduced":"2.1.0-p6"},{"last_affected":"2.1.0-p6"},{"introduced":"2.1.0-b7"},{"last_affected":"2.1.0-b7"},{"introduced":"2.1.0-p7"},{"last_affected":"2.1.0-p7"},{"introduced":"2.1.0-b8"},{"last_affected":"2.1.0-b8"},{"introduced":"2.1.0-p8"},{"last_affected":"2.1.0-p8"},{"introduced":"2.1.0-b9"},{"last_affected":"2.1.0-b9"},{"introduced":"2.1.0-p9"},{"last_affected":"2.1.0-p9"},{"introduced":"2.1.0-p10"},{"last_affected":"2.1.0-p10"},{"introduced":"2.1.0-p11"},{"last_affected":"2.1.0-p11"}],"source":"CPE_STRING"}}],"versions":["2.1.0-NA","2.1.0-b1","2.1.0-b2","2.1.0-b3","2.1.0-b4","2.1.0-b5","2.1.0-b6","2.1.0-b7","2.1.0-b8","2.1.0-b9","2.1.0-p10","2.1.0-p11","v2.1.0p11-rc2","v2.1.0p11","v2.1.0p11-rc1","v2.1.0p10","v2.1.0p9","v2.1.0p8","v2.1.0p7","v2.1.0p6","v2.1.0p5","v2.1.0p4","v2.1.0p3","v2.1.0p2","v2.1.0p1","v2.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-48321.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}