PT-2023-15698 · Checkmk · Checkmk
Jan Hörsch
·
Published
2023-02-20
·
Updated
2024-07-23
·
CVE-2022-48320
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Checkmk versions 1.6.0 and earlier
Checkmk versions 2.0.0 through 2.0.0p31
Checkmk versions 2.1.0 through 2.1.0p17
Description
The issue allows an attacker to perform Cross-site Request Forgery (CSRF) attacks, enabling them to add new visual elements to multiple pages. This can be achieved by exploiting the CSRF weakness in the affected Checkmk versions.
Recommendations
For Checkmk versions 1.6.0 and earlier, update to a version that is still supported and has the fix for this issue.
For Checkmk versions 2.0.0 through 2.0.0p31, update to version 2.0.0p32 or later.
For Checkmk versions 2.1.0 through 2.1.0p17, update to version 2.1.0p18 or later.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Checkmk