First published: Mon Sep 02 2024(Updated: )
Improper neutralization of input in Checkmk before version 2.3.0p14 allows attackers to inject and run malicious scripts in the Robotmk logs view.
Credit: security@checkmk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Checkmk NagVis | <2.3.0 | |
Checkmk NagVis | =2.3.0 | |
Checkmk NagVis | =2.3.0-p1 | |
Checkmk NagVis | =2.3.0-p10 | |
Checkmk NagVis | =2.3.0-p11 | |
Checkmk NagVis | =2.3.0-p12 | |
Checkmk NagVis | =2.3.0-p13 | |
Checkmk NagVis | =2.3.0-p2 | |
Checkmk NagVis | =2.3.0-p3 | |
Checkmk NagVis | =2.3.0-p4 | |
Checkmk NagVis | =2.3.0-p5 | |
Checkmk NagVis | =2.3.0-p6 | |
Checkmk NagVis | =2.3.0-p7 | |
Checkmk NagVis | =2.3.0-p8 | |
Checkmk NagVis | =2.3.0-p9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-38858 has a medium severity rating due to the potential for script injection.
To fix CVE-2024-38858, upgrade to Checkmk version 2.3.0p14 or later.
CVE-2024-38858 affects Checkmk versions prior to 2.3.0p14.
CVE-2024-38858 is an instance of improper neutralization of input.
Yes, CVE-2024-38858 allows attackers to inject malicious scripts in the Robotmk logs view.