CVE-2014-2329: XSS
Multiple cross-site scripting (XSS) vulnerabilities in CheckMK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allow remote authenticated users to inject arbitrary web script or HTML via the (1) agent string for a checkmk agent, a (2) crafted request to a monitored host, which is not properly handled by the logwatch module, or other unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2329?
CVE-2014-2329 has a medium severity rating due to its potential for exploitation through cross-site scripting (XSS).
How do I fix CVE-2014-2329?
To fix CVE-2014-2329, upgrade Check_MK to version 1.2.2p3 or above for 1.2.2 releases, or version 1.2.3i5 or above for 1.2.3 releases.
Who is affected by CVE-2014-2329?
CVE-2014-2329 affects Check_MK versions prior to 1.2.2p3 and 1.2.3i5, specifically installations of the Check_MK monitoring tool.
What types of attacks does CVE-2014-2329 enable?
CVE-2014-2329 enables remote authenticated users to inject arbitrary web scripts or HTML through cross-site scripting vulnerabilities.
Can CVE-2014-2329 be exploited by unauthenticated users?
No, CVE-2014-2329 can only be exploited by remote authenticated users with access to the Check_MK environment.