CVE-2022-24565: XSS
Checkmk <=2.0.0p19 Fixed in 2.0.0p20 and Checkmk <=1.6.0p27 Fixed in 1.6.0p28 are affected by a Cross Site Scripting (XSS) vulnerability. The Alias of a site was not properly escaped when shown as condition for notifications.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-24565?
The severity of CVE-2022-24565 is medium with a severity value of 5.4.
What is affected by CVE-2022-24565?
Checkmk versions 1.6.0p19 and below, as well as 2.0.0p19 and below are affected by CVE-2022-24565.
How does CVE-2022-24565 affect Checkmk?
CVE-2022-24565 is a Cross Site Scripting (XSS) vulnerability that affects Checkmk by improperly escaping the Alias of a site when shown as a condition for notifications.
How can I fix CVE-2022-24565?
To fix CVE-2022-24565, update Checkmk to version 2.0.0p20 or higher, or version 1.6.0p28 or higher.
Where can I find more information about CVE-2022-24565?
You can find more information about CVE-2022-24565 at the following reference: [link](https://checkmk.com/werk/13716)