CVE-2024-38858: Cross-site scripting in Robotmk logs view
Published Sep 2, 2024
·Updated
Improper neutralization of input in Checkmk before version 2.3.0p14 allows attackers to inject and run malicious scripts in the Robotmk logs view.
Affected Software
15 affected components
CheckMK Checkmk<2.3.0
CheckMK Checkmk=2.3.0
CheckMK Checkmk=2.3.0-p1
CheckMK Checkmk=2.3.0-p10
CheckMK Checkmk=2.3.0-p11
CheckMK Checkmk=2.3.0-p12
CheckMK Checkmk=2.3.0-p13
CheckMK Checkmk=2.3.0-p2
CheckMK Checkmk=2.3.0-p3
CheckMK Checkmk=2.3.0-p4
CheckMK Checkmk=2.3.0-p5
CheckMK Checkmk=2.3.0-p6
CheckMK Checkmk=2.3.0-p7
CheckMK Checkmk=2.3.0-p8
CheckMK Checkmk=2.3.0-p9
Event History
Sep 2, 2024
CVE Published
via MITRE·09:16 AM
Data Sourced
via MITRE·09:16 AM
DescriptionWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-38858?
CVE-2024-38858 has a medium severity rating due to the potential for script injection.
2
How do I fix CVE-2024-38858?
To fix CVE-2024-38858, upgrade to Checkmk version 2.3.0p14 or later.
3
What software is affected by CVE-2024-38858?
CVE-2024-38858 affects Checkmk versions prior to 2.3.0p14.
4
What type of vulnerability is CVE-2024-38858?
CVE-2024-38858 is an instance of improper neutralization of input.
5
Can CVE-2024-38858 affect my system's logs?
Yes, CVE-2024-38858 allows attackers to inject malicious scripts in the Robotmk logs view.