CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a backdoor on the device with HTML content and interpreted by the browser (such as JavaScript or other client-side scripts) or to steal the session cookies of a user who has previously authenticated via a man in the middle. Successful exploitation requires access to the web service resource without authentication.
{
"versions": [
{
"introduced": "1.5.0"
},
{
"fixed": "1.6.0"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-b1"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-b10"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-b12"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-b3"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-b4"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-b5"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-b9"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-p1"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-p10"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-p11"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-p12"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-p13"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-p14"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-p15"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-p16"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-p19"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-p2"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-p20"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-p21"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-p22"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-p23"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-p24"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-p25"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-p3"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-p4"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-p5"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-p6"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-p7"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-p8"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0-p9"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0b10"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0b11"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0p10"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0p17"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0p18"
}
]
}