Checkmk <=2.0.0p19 contains a Cross Site Scripting (XSS) vulnerability. While creating or editing a user attribute, the Help Text is subject to HTML injection, which can be triggered for editing a user.
| Software | From | Fixed in |
|---|---|---|
| checkmk / checkmk | 2.0.0-p19 | 2.0.0-p19.x |
| checkmk / checkmk | 2.0.0 | 2.0.0.x |
| checkmk / checkmk | 2.0.0-b1 | 2.0.0-b1.x |
| checkmk / checkmk | 2.0.0-b2 | 2.0.0-b2.x |
| checkmk / checkmk | 2.0.0-b3 | 2.0.0-b3.x |
| checkmk / checkmk | 2.0.0-b4 | 2.0.0-b4.x |
| checkmk / checkmk | 2.0.0-b5 | 2.0.0-b5.x |
| checkmk / checkmk | 2.0.0-b6 | 2.0.0-b6.x |
| checkmk / checkmk | 2.0.0-b7 | 2.0.0-b7.x |
| checkmk / checkmk | 2.0.0-b8 | 2.0.0-b8.x |
| checkmk / checkmk | 2.0.0-i1 | 2.0.0-i1.x |
| checkmk / checkmk | 2.0.0-p1 | 2.0.0-p1.x |
| checkmk / checkmk | 2.0.0-p10 | 2.0.0-p10.x |
| checkmk / checkmk | 2.0.0-p11 | 2.0.0-p11.x |
| checkmk / checkmk | 2.0.0-p12 | 2.0.0-p12.x |
| checkmk / checkmk | 2.0.0-p13 | 2.0.0-p13.x |
| checkmk / checkmk | 2.0.0-p14 | 2.0.0-p14.x |
| checkmk / checkmk | 2.0.0-p15 | 2.0.0-p15.x |
| checkmk / checkmk | 2.0.0-p16 | 2.0.0-p16.x |
| checkmk / checkmk | 2.0.0-p17 | 2.0.0-p17.x |
| checkmk / checkmk | 2.0.0-p18 | 2.0.0-p18.x |