Shinken Solutions Shinken Monitoring vulnerable to Incorrect Access Control
Critical severity
GitHub Reviewed
Published
Oct 20, 2022
to the GitHub Advisory Database
•
Updated Aug 17, 2023
Description
Published by the National Vulnerability Database
Oct 20, 2022
Published to the GitHub Advisory Database
Oct 20, 2022
Reviewed
Oct 20, 2022
Last updated
Aug 17, 2023
Shinken Solutions Shinken Monitoring Version 2.4.3 affected is vulnerable to Incorrect Access Control. The
SafeUnpickler
class found inshinken/safepickle.py
implements a weak authentication scheme when unserializing objects passed from monitoring nodes to the Shinken monitoring server.References