Werk #14509: add authentication to REST API documentation

Komponente REST API
Titel add authentication to REST API documentation
Datum 27.09.2022
Level Kleine Änderung
Klasse Sicherheitsfix
Kompatibilität Kompatibel - benötigt kein manuelles Eingreifen
Checkmk versions & editions
2.2.0b1 Checkmk Raw (CRE), Checkmk Enterprise (CEE), Checkmk Cloud (CCE), Checkmk MSP (CME)
2.1.0p14 Checkmk Raw (CRE), Checkmk Enterprise (CEE), Checkmk MSP (CME)
2.0.0p30 Checkmk Raw (CRE), Checkmk Enterprise (CEE), Checkmk MSP (CME)

It was previously not required to be authenticated to access the site's REST API documentation.

Because custom user tags and comments may appear in the automatically generated documentation, this would represent an "information leak". Therefore, from this Werk onwards, the site's REST API documentation is only allowed to be accessed by logged in users.

Vulnerability Management: We have rated the issue with a CVSS Score of 5.3 (Medium) with the following CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N. We have assigned CVE-2022-48318 for this issue.

Zur Liste aller Werks