CVE Database
/

CVE-2024-38863

Back to search

CVE-2024-38863

Published: Oct 14, 2024

Modified: Oct 14, 2024

PUBLISHED

Description

Exposure of CSRF tokens in query parameters on specific requests in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35 and <2.1.0p48 could lead to a leak of the token to facilitate targeted phishing attacks.

VendorProductVersions

Checkmk GmbH

Checkmk

affected
2.1.0 - < 2.1.0p48
affected
2.2.0 - < 2.2.0p35
affected
2.3.0 - < 2.3.0p18

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now