PT-2024-28244 · Checkmk · Checkmk
Published
2024-10-14
·
Updated
2024-12-03
·
CVE-2024-38863
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Checkmk versions prior to 2.3.0p18
Checkmk versions prior to 2.2.0p35
Checkmk versions prior to 2.1.0p48
Description
Exposure of CSRF tokens in query parameters on specific requests could lead to a leak of the token, facilitating targeted phishing attacks.
Recommendations
For versions prior to 2.3.0p18, update to version 2.3.0p18 or later.
For versions prior to 2.2.0p35, update to version 2.2.0p35 or later.
For versions prior to 2.1.0p48, update to version 2.1.0p48 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Checkmk