CVE-2022-24566 (GCVE-0-2022-24566)
Vulnerability from cvelistv5
Published
2022-02-23 10:52
Modified
2024-08-03 04:13
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- n/a
Summary
In Checkmk <=2.0.0p19 fixed in 2.0.0p20 and Checkmk <=1.6.0p27 fixed in 1.6.0p28, the title of a Predefined condition is not properly escaped when shown as condition, which can result in Cross Site Scripting (XSS).
References
► | URL | Tags | |||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
|
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-03T04:13:56.692Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://checkmk.com/werk/13717" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "n/a", "vendor": "n/a", "versions": [ { "status": "affected", "version": "n/a" } ] } ], "descriptions": [ { "lang": "en", "value": "In Checkmk \u003c=2.0.0p19 fixed in 2.0.0p20 and Checkmk \u003c=1.6.0p27 fixed in 1.6.0p28, the title of a Predefined condition is not properly escaped when shown as condition, which can result in Cross Site Scripting (XSS)." } ], "problemTypes": [ { "descriptions": [ { "description": "n/a", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2022-02-23T10:52:06", "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "shortName": "mitre" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://checkmk.com/werk/13717" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2022-24566", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "In Checkmk \u003c=2.0.0p19 fixed in 2.0.0p20 and Checkmk \u003c=1.6.0p27 fixed in 1.6.0p28, the title of a Predefined condition is not properly escaped when shown as condition, which can result in Cross Site Scripting (XSS)." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "name": "https://checkmk.com/werk/13717", "refsource": "MISC", "url": "https://checkmk.com/werk/13717" } ] } } } }, "cveMetadata": { "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "assignerShortName": "mitre", "cveId": "CVE-2022-24566", "datePublished": "2022-02-23T10:52:06", "dateReserved": "2022-02-07T00:00:00", "dateUpdated": "2024-08-03T04:13:56.692Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1", "vulnerability-lookup:meta": { "nvd": "{\"cve\":{\"id\":\"CVE-2022-24566\",\"sourceIdentifier\":\"cve@mitre.org\",\"published\":\"2022-02-24T15:15:29.553\",\"lastModified\":\"2024-11-21T06:50:40.187\",\"vulnStatus\":\"Modified\",\"cveTags\":[],\"descriptions\":[{\"lang\":\"en\",\"value\":\"In Checkmk \u003c=2.0.0p19 fixed in 2.0.0p20 and Checkmk \u003c=1.6.0p27 fixed in 1.6.0p28, the title of a Predefined condition is not properly escaped when shown as condition, which can result in Cross Site Scripting (XSS).\"},{\"lang\":\"es\",\"value\":\"En Checkmk versiones anteriores a 2.0.0p19 incluy\u00e9ndola, corregido en 2.0.0p20 y Checkmk versiones anteriores a 1.6.0p27 incluy\u00e9ndola, corregido en 1.6.0p28, el t\u00edtulo de una condici\u00f3n predefinida no es escapado apropiadamente cuando es mostrado como condici\u00f3n, lo que puede resultar en un ataque de tipo Cross Site Scripting (XSS)\"}],\"metrics\":{\"cvssMetricV31\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"3.1\",\"vectorString\":\"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N\",\"baseScore\":5.4,\"baseSeverity\":\"MEDIUM\",\"attackVector\":\"NETWORK\",\"attackComplexity\":\"LOW\",\"privilegesRequired\":\"LOW\",\"userInteraction\":\"REQUIRED\",\"scope\":\"CHANGED\",\"confidentialityImpact\":\"LOW\",\"integrityImpact\":\"LOW\",\"availabilityImpact\":\"NONE\"},\"exploitabilityScore\":2.3,\"impactScore\":2.7}],\"cvssMetricV2\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"2.0\",\"vectorString\":\"AV:N/AC:M/Au:S/C:N/I:P/A:N\",\"baseScore\":3.5,\"accessVector\":\"NETWORK\",\"accessComplexity\":\"MEDIUM\",\"authentication\":\"SINGLE\",\"confidentialityImpact\":\"NONE\",\"integrityImpact\":\"PARTIAL\",\"availabilityImpact\":\"NONE\"},\"baseSeverity\":\"LOW\",\"exploitabilityScore\":6.8,\"impactScore\":2.9,\"acInsufInfo\":false,\"obtainAllPrivilege\":false,\"obtainUserPrivilege\":false,\"obtainOtherPrivilege\":false,\"userInteractionRequired\":true}]},\"weaknesses\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"description\":[{\"lang\":\"en\",\"value\":\"CWE-79\"}]}],\"configurations\":[{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:1.6.0:-:*:*:*:*:*:*\",\"matchCriteriaId\":\"5D63367A-3B90-462E-B6AD-1CB5721FD45E\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:1.6.0:b1:*:*:*:*:*:*\",\"matchCriteriaId\":\"E5E2E954-B3C3-4CC0-B2C8-0E2BEEC93016\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:1.6.0:b10:*:*:*:*:*:*\",\"matchCriteriaId\":\"1638594A-84F1-44F6-BB30-D4CC73ECDA38\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:1.6.0:b12:*:*:*:*:*:*\",\"matchCriteriaId\":\"7B2757BF-E3B7-487A-8929-0208D3B0D3CE\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:1.6.0:b3:*:*:*:*:*:*\",\"matchCriteriaId\":\"F01E79D2-EFA4-4A7E-A286-3E86F52B429D\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:1.6.0:b4:*:*:*:*:*:*\",\"matchCriteriaId\":\"D12A6070-0542-4293-AE13-85D4E81E1672\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:1.6.0:b5:*:*:*:*:*:*\",\"matchCriteriaId\":\"6AF633FE-DE7C-4548-9ED2-880E915FC33C\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:1.6.0:b9:*:*:*:*:*:*\",\"matchCriteriaId\":\"F15190EF-E3F5-4AD1-B748-C0E63C8CB741\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:1.6.0:p1:*:*:*:*:*:*\",\"matchCriteriaId\":\"30F84B89-7EC6-44E6-A164-4C170379D55C\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:1.6.0:p10:*:*:*:*:*:*\",\"matchCriteriaId\":\"DDA94D2F-F27C-4DF6-84AE-8ED1BBC7F61E\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:1.6.0:p11:*:*:*:*:*:*\",\"matchCriteriaId\":\"71CF8EFD-17F6-4D9A-961A-4B949A6C8B61\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:1.6.0:p12:*:*:*:*:*:*\",\"matchCriteriaId\":\"B04DC2A8-CF05-4FB2-AE2F-AE07943B998D\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:1.6.0:p13:*:*:*:*:*:*\",\"matchCriteriaId\":\"1F3BECA6-983C-436E-A635-4E1FB9080E56\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:1.6.0:p14:*:*:*:*:*:*\",\"matchCriteriaId\":\"51A9A2B4-3693-490A-94E2-64E1DB795646\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:1.6.0:p15:*:*:*:*:*:*\",\"matchCriteriaId\":\"C14AB385-8A9F-46FA-A1C5-4A4A45C1B7F5\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:1.6.0:p16:*:*:*:*:*:*\",\"matchCriteriaId\":\"EC41CC5F-F088-4E65-B076-35665F0F6C7E\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:1.6.0:p19:*:*:*:*:*:*\",\"matchCriteriaId\":\"EC636B76-B050-4B73-A524-21862B020797\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:1.6.0:p2:*:*:*:*:*:*\",\"matchCriteriaId\":\"D49B1D63-8FDD-45FD-99F0-AA9E4FBCCB00\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:1.6.0:p20:*:*:*:*:*:*\",\"matchCriteriaId\":\"8AFA4AF4-8395-4BBB-BA78-7116AC1DCDE7\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:1.6.0:p21:*:*:*:*:*:*\",\"matchCriteriaId\":\"5565C1C5-5C23-4449-AB87-49A304382387\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:1.6.0:p22:*:*:*:*:*:*\",\"matchCriteriaId\":\"78320525-F346-4419-81E3-4A47BD17C808\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:1.6.0:p23:*:*:*:*:*:*\",\"matchCriteriaId\":\"EA91018D-DA38-4026-9F47-383F16C85031\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:1.6.0:p24:*:*:*:*:*:*\",\"matchCriteriaId\":\"E8DBEF67-A9AE-46D5-89D0-076CDB1AA06A\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:1.6.0:p25:*:*:*:*:*:*\",\"matchCriteriaId\":\"63E87316-1CB2-4CF4-B379-4284C8C39053\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:1.6.0:p26:*:*:*:*:*:*\",\"matchCriteriaId\":\"75925C19-FBF4-4908-B8AD-E19E13B665DB\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:1.6.0:p27:*:*:*:*:*:*\",\"matchCriteriaId\":\"66FC7193-674F-42AA-8064-93786B5474C1\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:2.0.0:-:*:*:*:*:*:*\",\"matchCriteriaId\":\"F8EDFDCA-0778-4540-B1D5-D3A986258028\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:2.0.0:b1:*:*:*:*:*:*\",\"matchCriteriaId\":\"54031390-D7E7-4A14-AA2F-923768B3685F\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:2.0.0:b2:*:*:*:*:*:*\",\"matchCriteriaId\":\"F1B7E35F-5A07-424E-AA09-AC54104D612B\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:2.0.0:b3:*:*:*:*:*:*\",\"matchCriteriaId\":\"8D4AC302-C8F5-4A2B-A73A-982D0AA2495A\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:2.0.0:b4:*:*:*:*:*:*\",\"matchCriteriaId\":\"7A058C71-C39E-4109-B570-4A061013D033\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:2.0.0:b5:*:*:*:*:*:*\",\"matchCriteriaId\":\"22BCFA79-B3D6-4FFF-A3D3-8C4C97AF17C5\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:2.0.0:b6:*:*:*:*:*:*\",\"matchCriteriaId\":\"2A1703D9-8EEB-432D-90E2-F847CDC4C204\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:2.0.0:b7:*:*:*:*:*:*\",\"matchCriteriaId\":\"1A4C72BA-6D78-4911-83E4-4DABB2CAC47F\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:2.0.0:b8:*:*:*:*:*:*\",\"matchCriteriaId\":\"081FD127-1066-4019-B521-9FADB85DBD4A\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:2.0.0:i1:*:*:*:*:*:*\",\"matchCriteriaId\":\"C1A4F005-4823-4B2B-B4EF-4EFDB04CFB9B\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:2.0.0:p1:*:*:*:*:*:*\",\"matchCriteriaId\":\"357240B1-F0DA-4FA8-B782-D998951F4B54\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:2.0.0:p10:*:*:*:*:*:*\",\"matchCriteriaId\":\"2F828F54-04E2-4B98-91A7-B09ED833E88B\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:2.0.0:p11:*:*:*:*:*:*\",\"matchCriteriaId\":\"A4B8B300-8264-40AB-A839-7EACB988163B\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:2.0.0:p12:*:*:*:*:*:*\",\"matchCriteriaId\":\"EB76A8DF-C870-482F-A488-DB2917ABD971\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:2.0.0:p13:*:*:*:*:*:*\",\"matchCriteriaId\":\"04947B1B-CF67-4C11-8FE3-6C17FD35E2EF\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:2.0.0:p14:*:*:*:*:*:*\",\"matchCriteriaId\":\"591AEC3C-2F48-4E91-9881-42EEDD039C5D\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:2.0.0:p15:*:*:*:*:*:*\",\"matchCriteriaId\":\"C5CA04C8-2C80-4C7E-B329-3FFCBEDEE663\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:2.0.0:p16:*:*:*:*:*:*\",\"matchCriteriaId\":\"47A1C5AC-C8B7-495A-A5F4-CD4790358A2E\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:2.0.0:p17:*:*:*:*:*:*\",\"matchCriteriaId\":\"B87D8B46-5B04-460D-BBA1-BB19234DA19D\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:2.0.0:p18:*:*:*:*:*:*\",\"matchCriteriaId\":\"C59EA30A-0B7D-4E58-A503-8C2F16B45004\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:checkmk:checkmk:2.0.0:p19:*:*:*:*:*:*\",\"matchCriteriaId\":\"F2849E4C-09D1-48A5-B28E-F7A4CD3E8967\"}]}]}],\"references\":[{\"url\":\"https://checkmk.com/werk/13717\",\"source\":\"cve@mitre.org\",\"tags\":[\"Vendor Advisory\"]},{\"url\":\"https://checkmk.com/werk/13717\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Vendor Advisory\"]}]}}" } }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…