CVE-2024-2380: XSS in graph rendering
Published Apr 5, 2024
·Updated
Stored XSS in graph rendering in Checkmk <2.3.0b4.
Affected Software
3 affected components
CheckMK Checkmk=2.3.0-b1
CheckMK Checkmk=2.3.0-b2
CheckMK Checkmk=2.3.0-b3
Event History
Apr 5, 2024
CVE Published
via MITRE·01:01 PM
Data Sourced
via MITRE·01:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-2380?
CVE-2024-2380 is classified as a medium severity vulnerability due to its potential for causing stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2024-2380?
To fix CVE-2024-2380, upgrade to a version of Checkmk that is higher than 2.3.0-b3.
3
What versions of Checkmk are affected by CVE-2024-2380?
CVE-2024-2380 affects Checkmk versions 2.3.0-b1, 2.3.0-b2, and 2.3.0-b3.
4
What does stored XSS mean in CVE-2024-2380?
Stored XSS in CVE-2024-2380 refers to the vulnerability allowing malicious scripts to be saved and executed in users' browsers.
5
Who is impacted by CVE-2024-2380?
Users of Checkmk versions 2.3.0-b1, 2.3.0-b2, and 2.3.0-b3 are at risk from CVE-2024-2380.