2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2022-24566" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2022-02-24T15:15:29.553" ,
"lastModified" : "2022-03-02T18:10:29.777" ,
"vulnStatus" : "Analyzed" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "In Checkmk <=2.0.0p19 fixed in 2.0.0p20 and Checkmk <=1.6.0p27 fixed in 1.6.0p28, the title of a Predefined condition is not properly escaped when shown as condition, which can result in Cross Site Scripting (XSS)."
} ,
{
"lang" : "es" ,
"value" : "En Checkmk versiones anteriores a 2.0.0p19 incluy\u00e9ndola, corregido en 2.0.0p20 y Checkmk versiones anteriores a 1.6.0p27 incluy\u00e9ndola, corregido en 1.6.0p28, el t\u00edtulo de una condici\u00f3n predefinida no es escapado apropiadamente cuando es mostrado como condici\u00f3n, lo que puede resultar en un ataque de tipo Cross Site Scripting (XSS)"
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "REQUIRED" ,
"scope" : "CHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 5.4 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 2.3 ,
"impactScore" : 2.7
}
] ,
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N" ,
"accessVector" : "NETWORK" ,
"accessComplexity" : "MEDIUM" ,
"authentication" : "SINGLE" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "PARTIAL" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 3.5
} ,
"baseSeverity" : "LOW" ,
"exploitabilityScore" : 6.8 ,
"impactScore" : 2.9 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : true
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-79"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0:-:*:*:*:*:*:*" ,
"matchCriteriaId" : "E15C521C-CD7F-434A-9F43-6ED5C7645DA7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0:b1:*:*:*:*:*:*" ,
"matchCriteriaId" : "172724CA-44E1-4768-8BAF-611AE72C8510"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0:b10:*:*:*:*:*:*" ,
"matchCriteriaId" : "EE1C7D4B-55E2-4A0B-96AD-4D1645141B43"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0:b12:*:*:*:*:*:*" ,
"matchCriteriaId" : "7B691D90-C811-43A1-8062-71F2BF0EF5E7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0:b3:*:*:*:*:*:*" ,
"matchCriteriaId" : "99D39BA7-C78A-4667-95F1-55ACB9FD584F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0:b4:*:*:*:*:*:*" ,
"matchCriteriaId" : "5B467203-3B24-4CAE-BEB4-88FEFA2223EF"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0:b5:*:*:*:*:*:*" ,
"matchCriteriaId" : "FDEC890E-D96A-490D-988D-B06C6CD86A05"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0:b9:*:*:*:*:*:*" ,
"matchCriteriaId" : "DB52C0F4-B206-4F20-BDB7-3FF2E60185D1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0:p1:*:*:*:*:*:*" ,
"matchCriteriaId" : "D80533C1-AA9F-481B-A4A4-26AA0695C666"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0:p10:*:*:*:*:*:*" ,
"matchCriteriaId" : "FA0AD652-2417-4C33-8299-0411FA002BAF"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0:p11:*:*:*:*:*:*" ,
"matchCriteriaId" : "29F70025-92A2-4618-A8DD-05098F45625F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0:p12:*:*:*:*:*:*" ,
"matchCriteriaId" : "9CAAB02A-CB2D-42F9-9720-520822F88402"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0:p13:*:*:*:*:*:*" ,
"matchCriteriaId" : "46C5993C-BEE1-4C9B-BCDB-09A36DA2485E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0:p14:*:*:*:*:*:*" ,
"matchCriteriaId" : "53E01ABC-75DA-4323-9E8C-F97321974583"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0:p15:*:*:*:*:*:*" ,
"matchCriteriaId" : "77427E05-C4A1-4C28-84B8-947E26CF7EA8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0:p16:*:*:*:*:*:*" ,
"matchCriteriaId" : "6036F586-CA74-40DE-B76F-C76357A1E833"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0:p19:*:*:*:*:*:*" ,
"matchCriteriaId" : "84B6760F-4EB5-47C2-BDB1-9D654826B01D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0:p2:*:*:*:*:*:*" ,
"matchCriteriaId" : "104EB827-02D7-4AB9-897D-16210E8934D6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0:p20:*:*:*:*:*:*" ,
"matchCriteriaId" : "232E5841-8303-410C-9191-F9603B808AB1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0:p21:*:*:*:*:*:*" ,
"matchCriteriaId" : "B9276429-8D0B-4647-AFBE-9A0B158666D1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0:p22:*:*:*:*:*:*" ,
"matchCriteriaId" : "86E4613C-C843-473F-B7BE-E5759D8D35B4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0:p23:*:*:*:*:*:*" ,
"matchCriteriaId" : "0FBD73A9-AF27-402E-9B42-B9DF1567CF43"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0:p24:*:*:*:*:*:*" ,
"matchCriteriaId" : "9EEBA5A8-5330-47A8-9D3E-08A7E22F70C9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0:p25:*:*:*:*:*:*" ,
"matchCriteriaId" : "3A5E5E38-94BA-4708-80A4-25CF71074E82"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0:p26:*:*:*:*:*:*" ,
"matchCriteriaId" : "28FA4030-59CF-43CB-A9B7-E2304E2315DC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0:p27:*:*:*:*:*:*" ,
"matchCriteriaId" : "1E00E39E-522C-4FDD-B4D7-0444FFC120ED"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.0.0:-:*:*:*:*:*:*" ,
"matchCriteriaId" : "E5138E25-A5AF-495D-A713-B8BDACC133D8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.0.0:b1:*:*:*:*:*:*" ,
"matchCriteriaId" : "7AE78B5E-2D00-462B-AC0E-5E68BC36ED1B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.0.0:b2:*:*:*:*:*:*" ,
"matchCriteriaId" : "9D69AA9A-C6FF-4A9F-8B02-2F207C4150FD"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.0.0:b3:*:*:*:*:*:*" ,
"matchCriteriaId" : "452F359B-BCB5-46E0-A77A-383C3C2E2D60"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.0.0:b4:*:*:*:*:*:*" ,
"matchCriteriaId" : "D9A66C28-A2BA-4091-AB4C-05CDB1D3777F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.0.0:b5:*:*:*:*:*:*" ,
"matchCriteriaId" : "463A4A68-810B-4C20-A696-4F94DB20224B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.0.0:b6:*:*:*:*:*:*" ,
"matchCriteriaId" : "F4459581-214F-423B-A29D-31C789FD7F1C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.0.0:b7:*:*:*:*:*:*" ,
"matchCriteriaId" : "CC0CFABC-A53C-4FD3-A57A-CB72C87A034B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.0.0:b8:*:*:*:*:*:*" ,
"matchCriteriaId" : "F96B08FA-8129-4880-86FE-47B08C2B6964"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.0.0:i1:*:*:*:*:*:*" ,
"matchCriteriaId" : "CAEB960C-5A5E-4F7C-8588-3F6737AE5DCA"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.0.0:p1:*:*:*:*:*:*" ,
"matchCriteriaId" : "3CB134CD-0746-47C8-BAB8-2AE9C083C4D2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.0.0:p10:*:*:*:*:*:*" ,
"matchCriteriaId" : "E4B5DDAA-F7B5-4BFD-836E-F7DA0FC7B0C3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.0.0:p11:*:*:*:*:*:*" ,
"matchCriteriaId" : "A4DA5440-F376-4952-ABCB-AC557C5944A9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.0.0:p12:*:*:*:*:*:*" ,
"matchCriteriaId" : "DB7DB93B-CDD2-4662-893B-6E36F9EDA7FF"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.0.0:p13:*:*:*:*:*:*" ,
"matchCriteriaId" : "81DFD64A-FEFD-4EBA-B6EC-28D3F0EEC33B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.0.0:p14:*:*:*:*:*:*" ,
"matchCriteriaId" : "918ACC6A-2EE8-401F-B18A-94B8757B202E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.0.0:p15:*:*:*:*:*:*" ,
"matchCriteriaId" : "1B6AE143-5A29-4EE8-AF7D-5D495A2248D0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.0.0:p16:*:*:*:*:*:*" ,
"matchCriteriaId" : "9B678D96-5987-4423-A713-57812B896380"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.0.0:p17:*:*:*:*:*:*" ,
"matchCriteriaId" : "A16EA6BD-003D-416E-B6C7-EBE5AA4AC2B5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.0.0:p18:*:*:*:*:*:*" ,
"matchCriteriaId" : "7A016627-9BF2-4D25-AB97-172EAEC4C187"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:2.0.0:p19:*:*:*:*:*:*" ,
"matchCriteriaId" : "333FBE01-E5C1-4668-B50F-B64A34E799A8"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://checkmk.com/werk/13717" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Vendor Advisory"
]
}
]
}