CVE-2024-28832: XSS in Crash Report Page
Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users with permission to change Global Settings to execute arbitrary scripts by injecting HTML elements into the Crash Report URL in the Global Settings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28832?
CVE-2024-28832 is classified as a stored cross-site scripting (XSS) vulnerability.
How can I fix CVE-2024-28832?
To mitigate CVE-2024-28832, it is recommended to upgrade to Checkmk versions 2.3.0p7, 2.2.0p28, 2.1.0p45, or later.
What versions of Checkmk are affected by CVE-2024-28832?
CVE-2024-28832 affects Checkmk versions before 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0.
Who is vulnerable to CVE-2024-28832?
Users with permission to change Global Settings in affected Checkmk versions are vulnerable to CVE-2024-28832.
What kinds of attacks can CVE-2024-28832 enable?
CVE-2024-28832 can enable attackers to execute arbitrary scripts by injecting HTML elements into the Crash Report page.