CVE-2024-28828: 1-Click compromize via CSRF
Cross-Site request forgery in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) could lead to 1-click compromize of the site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28828?
CVE-2024-28828 is classified as a high severity vulnerability due to its potential for one-click compromise of the affected Checkmk installations.
How do I fix CVE-2024-28828?
To mitigate CVE-2024-28828, upgrade your Checkmk installation to version 2.3.0p8 or later, or to 2.2.0p29, 2.1.0p45, or 2.0.0p39 and higher.
Which versions of Checkmk are affected by CVE-2024-28828?
CVE-2024-28828 affects Checkmk versions lower than 2.3.0p8, 2.2.0p29, 2.1.0p45, and 2.0.0p39.
What kind of attack does CVE-2024-28828 enable?
CVE-2024-28828 enables cross-site request forgery (CSRF) attacks, allowing an attacker to execute actions on behalf of a victim user.
Is there a workaround for CVE-2024-28828?
There is no specific workaround for CVE-2024-28828; the recommended action is to update to a fixed version as soon as possible.