Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-13722

Опубликовано: 04 фев. 2025
Источник: debian
EPSS Низкий

Описание

The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
check-mkremovedpackage
nagvisfixed1:1.9.42-1package
nagvisno-dsabookwormpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2025/02/04/3

EPSS

Процентиль: 11%
0.0004
Низкий

Связанные уязвимости

CVSS3: 5.4
ubuntu
6 месяцев назад

The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users.

CVSS3: 5.4
nvd
6 месяцев назад

The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users.

CVSS3: 5.4
github
6 месяцев назад

The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users.

EPSS

Процентиль: 11%
0.0004
Низкий
Уязвимость CVE-2024-13722