CVE-2024-38859: XSS in view page with SLA column
XSS in the view page with the SLA column configured in Checkmk versions prior to 2.3.0p14, 2.2.0p33, 2.1.0p47 and 2.0.0 (EOL) allowed malicious users to execute arbitrary scripts by injecting HTML elements into the SLA column title. These scripts could be executed when the view page was cloned by other users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38859?
CVE-2024-38859 has a severity rating that allows attackers to execute arbitrary scripts through Cross-Site Scripting (XSS) vulnerabilities.
How do I fix CVE-2024-38859?
To fix CVE-2024-38859, upgrade to Checkmk versions 2.3.0p14, 2.2.0p33, 2.1.0p47, or later.
Which versions of Checkmk are affected by CVE-2024-38859?
CVE-2024-38859 affects Checkmk versions prior to 2.3.0p14, 2.2.0p33, 2.1.0p47, and 2.0.0.
What type of vulnerability is CVE-2024-38859?
CVE-2024-38859 is a Cross-Site Scripting (XSS) vulnerability that can be exploited through the SLA column in Checkmk.
Who is impacted by CVE-2024-38859?
Users of Checkmk running vulnerable versions before the specified patches are at risk of exploitation from this vulnerability.