Lucene search

K
nvd[email protected]NVD:CVE-2024-38858
HistorySep 02, 2024 - 12:15 p.m.

CVE-2024-38858

2024-09-0212:15:19
CWE-79
web.nvd.nist.gov
5
checkmk
input neutralization
injection
malicious scripts
robotmk logs view

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

17.7%

Improper neutralization of input in Checkmk before version 2.3.0p14 allows attackers to inject and run malicious scripts in the Robotmk logs view.

Affected configurations

Nvd
Node
checkmkcheckmkRange<2.3.0
OR
checkmkcheckmkMatch2.3.0-
OR
checkmkcheckmkMatch2.3.0p1
OR
checkmkcheckmkMatch2.3.0p10
OR
checkmkcheckmkMatch2.3.0p11
OR
checkmkcheckmkMatch2.3.0p12
OR
checkmkcheckmkMatch2.3.0p13
OR
checkmkcheckmkMatch2.3.0p2
OR
checkmkcheckmkMatch2.3.0p3
OR
checkmkcheckmkMatch2.3.0p4
OR
checkmkcheckmkMatch2.3.0p5
OR
checkmkcheckmkMatch2.3.0p6
OR
checkmkcheckmkMatch2.3.0p7
OR
checkmkcheckmkMatch2.3.0p8
OR
checkmkcheckmkMatch2.3.0p9
VendorProductVersionCPE
checkmkcheckmk*cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*
checkmkcheckmk2.3.0cpe:2.3:a:checkmk:checkmk:2.3.0:-:*:*:*:*:*:*
checkmkcheckmk2.3.0cpe:2.3:a:checkmk:checkmk:2.3.0:p1:*:*:*:*:*:*
checkmkcheckmk2.3.0cpe:2.3:a:checkmk:checkmk:2.3.0:p10:*:*:*:*:*:*
checkmkcheckmk2.3.0cpe:2.3:a:checkmk:checkmk:2.3.0:p11:*:*:*:*:*:*
checkmkcheckmk2.3.0cpe:2.3:a:checkmk:checkmk:2.3.0:p12:*:*:*:*:*:*
checkmkcheckmk2.3.0cpe:2.3:a:checkmk:checkmk:2.3.0:p13:*:*:*:*:*:*
checkmkcheckmk2.3.0cpe:2.3:a:checkmk:checkmk:2.3.0:p2:*:*:*:*:*:*
checkmkcheckmk2.3.0cpe:2.3:a:checkmk:checkmk:2.3.0:p3:*:*:*:*:*:*
checkmkcheckmk2.3.0cpe:2.3:a:checkmk:checkmk:2.3.0:p4:*:*:*:*:*:*
Rows per page:
1-10 of 151

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

17.7%

Related for NVD:CVE-2024-38858