Improper restriction of excessive authentication attempts with two factor authentication methods in Checkmk 2.3 before 2.3.0p6 facilitates brute-forcing of second factor mechanisms.
| Software | From | Fixed in |
|---|---|---|
| checkmk / checkmk | 2.3.0-p1 | 2.3.0-p1.x |
| checkmk / checkmk | 2.3.0-p2 | 2.3.0-p2.x |
| checkmk / checkmk | 2.3.0-p3 | 2.3.0-p3.x |
| checkmk / checkmk | 2.3.0-p4 | 2.3.0-p4.x |
| checkmk / checkmk | 2.3.0-p5 | 2.3.0-p5.x |