Werk #1052: index start URL can not be used to redirect to absolute URLs anymore

Komponente User interface
Titel index start URL can not be used to redirect to absolute URLs anymore
Datum 04.07.2014
Level Kleine Änderung
Klasse Sicherheitsfix
Kompatibilität Kompatibel - benötigt kein manuelles Eingreifen
Checkmk versions & editions
1.2.5i5 Checkmk Raw (CRE), Checkmk Enterprise (CEE), Checkmk MSP (CME)

An attacker could make a user open up an URL to a compromised website which the does not want to open index.py?start_url=http://(url to compromised URL).

Zur Liste aller Werks