CVE-2022-24566

In Checkmk <=2.0.0p19 fixed in 2.0.0p20 and Checkmk <=1.6.0p27 fixed in 1.6.0p28, the title of a Predefined condition is not properly escaped when shown as condition, which can result in Cross Site Scripting (XSS).
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
VendorProductVersion
checkmkcheckmk
1.6.0
checkmkcheckmk
1.6.0:b1
checkmkcheckmk
1.6.0:b10
checkmkcheckmk
1.6.0:b12
checkmkcheckmk
1.6.0:b3
checkmkcheckmk
1.6.0:b4
checkmkcheckmk
1.6.0:b5
checkmkcheckmk
1.6.0:b9
checkmkcheckmk
1.6.0:p1
checkmkcheckmk
1.6.0:p10
checkmkcheckmk
1.6.0:p11
checkmkcheckmk
1.6.0:p12
checkmkcheckmk
1.6.0:p13
checkmkcheckmk
1.6.0:p14
checkmkcheckmk
1.6.0:p15
checkmkcheckmk
1.6.0:p16
checkmkcheckmk
1.6.0:p19
checkmkcheckmk
1.6.0:p2
checkmkcheckmk
1.6.0:p20
checkmkcheckmk
1.6.0:p21
checkmkcheckmk
1.6.0:p22
checkmkcheckmk
1.6.0:p23
checkmkcheckmk
1.6.0:p24
checkmkcheckmk
1.6.0:p25
checkmkcheckmk
1.6.0:p26
checkmkcheckmk
1.6.0:p27
checkmkcheckmk
2.0.0
checkmkcheckmk
2.0.0:b1
checkmkcheckmk
2.0.0:b2
checkmkcheckmk
2.0.0:b3
checkmkcheckmk
2.0.0:b4
checkmkcheckmk
2.0.0:b5
checkmkcheckmk
2.0.0:b6
checkmkcheckmk
2.0.0:b7
checkmkcheckmk
2.0.0:b8
checkmkcheckmk
2.0.0:i1
checkmkcheckmk
2.0.0:p1
checkmkcheckmk
2.0.0:p10
checkmkcheckmk
2.0.0:p11
checkmkcheckmk
2.0.0:p12
checkmkcheckmk
2.0.0:p13
checkmkcheckmk
2.0.0:p14
checkmkcheckmk
2.0.0:p15
checkmkcheckmk
2.0.0:p16
checkmkcheckmk
2.0.0:p17
checkmkcheckmk
2.0.0:p18
checkmkcheckmk
2.0.0:p19
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
check-mk
bionic
not-affected
xenial
not-affected
trusty
ignored