PT-2024-22596 · Checkmk · Checkmk
Published
2024-07-10
·
Updated
2024-08-07
·
CVE-2024-28828
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Checkmk versions < 2.3.0p8
Checkmk versions < 2.2.0p29
Checkmk versions < 2.1.0p45
Checkmk versions <= 2.0.0p39
Description
Cross-Site request forgery in Checkmk could lead to 1-click compromise of the site.
Recommendations
For Checkmk versions < 2.3.0p8, update to version 2.3.0p8 or later.
For Checkmk versions < 2.2.0p29, update to version 2.2.0p29 or later.
For Checkmk versions < 2.1.0p45, update to version 2.1.0p45 or later.
For Checkmk versions <= 2.0.0p39, update to a version later than 2.0.0p39, or consider alternative measures as this version is end-of-life.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Checkmk