CVE-2024-38863: CSRF token leaked in URL parameters
Exposure of CSRF tokens in query parameters on specific requests in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35 and <2.1.0p48 could lead to a leak of the token to facilitate targeted phishing attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38863?
CVE-2024-38863 is considered a moderate severity vulnerability due to the potential for targeted phishing attacks.
How do I fix CVE-2024-38863?
To fix CVE-2024-38863, upgrade your Checkmk installation to version 2.3.0p18 or later, or version 2.2.0p35 or later, or version 2.1.0p48 or later.
What types of systems are affected by CVE-2024-38863?
CVE-2024-38863 affects specific versions of Checkmk, including any version below 2.3.0p18, 2.2.0p35, and 2.1.0p48.
What does CVE-2024-38863 exploit?
CVE-2024-38863 exploits the exposure of CSRF tokens in query parameters on specific requests.
What can happen if CVE-2024-38863 is exploited?
If CVE-2024-38863 is exploited, it could lead to the leakage of CSRF tokens, facilitating phishing attacks.