We use cookies to ensure that we give you the best experience on our website.  Visit our Privacy Policy to learn more. If you continue to use this site, we will assume that you are okay with it.

Your choices regarding cookies on this site.
Your preferences have been updated.
In order for the changes to take effect completely please clear your browser cookies and cache. Then reload the page.

Werk #8881: Fix possible XSS issue on 'confirm failed notifications' page

ComponentGUI
TitleFix possible XSS issue on "confirm failed notifications" page
Date2019-09-04 09:44:46
Checkmk EditionCheckmk Raw Edition (CRE)
Checkmk Version1.6.0b9,1.7.0i1
LevelTrivial Change
ClassSecurity Fix
CompatibilityCompatible - no manual interaction needed

Using a manipulated notification script or notification destination system it was possible to inject javascript code into the "confirm failed notifications" page.

To prevent users from this potential issue, you could remove the permission for viewing the failed notifications from the users roles.