CVE-2022-24565
Published: 24 February 2022
Checkmk <=2.0.0p19 Fixed in 2.0.0p20 and Checkmk <=1.6.0p27 Fixed in 1.6.0p28 are affected by a Cross Site Scripting (XSS) vulnerability. The Alias of a site was not properly escaped when shown as condition for notifications.
Notes
Author | Note |
---|---|
0xnishit | fix 2.0.0p20: https://github.com/tribe29/checkmk/commit/03152e756198c4663d1f9880ba86c015712d9f18 fix 1.6.0p28: https://github.com/tribe29/checkmk/commit/b8d7b671786cb3261d3721aae39e77e69debd1a5 |
Priority
Severity score breakdown
Parameter | Value |
---|---|
Base score | 5.4 |
Attack vector | Network |
Attack complexity | Low |
Privileges required | Low |
User interaction | Required |
Scope | Changed |
Confidentiality | Low |
Integrity impact | Low |
Availability impact | None |
Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |