Description


Exposure of CSRF tokens in query parameters on specific requests in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35 and <2.1.0p48 could lead to a leak of the token to facilitate targeted phishing attacks.

Related CPE's


a

checkmk

checkmk

125

References


Weaknesses



CWE-598


NVD-CWE-Other

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.5 · High

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2024-10-14T06:15:02.823Z

1 year ago

Last modified

2024-12-03T15:47:15.693Z

1 year ago