Vulnerability Description
Exposure of CSRF tokens in query parameters on specific requests in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35 and <2.1.0p48 could lead to a leak of the token to facilitate targeted phishing attacks.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Checkmk | Checkmk | 2.1.0 |
Related Weaknesses (CWE)
References
- https://checkmk.com/werk/17096Vendor Advisory
FAQ
What is CVE-2024-38863?
CVE-2024-38863 is a vulnerability with a CVSS score of 7.5 (HIGH). Exposure of CSRF tokens in query parameters on specific requests in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35 and <2.1.0p48 could lead to a leak of the token to facilitate targeted phishing...
How severe is CVE-2024-38863?
CVE-2024-38863 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-38863?
Check the references section above for vendor advisories and patch information. Affected products include: Checkmk Checkmk.