Werk #4902: Monitoring history views: Fixed possible XSS when displaying "plugin output"

Komponente User interface
Titel Monitoring history views: Fixed possible XSS when displaying "plugin output"
Datum 27.06.2017
Checkmk Edition Checkmk Raw (CRE)
Checkmk-Version 1.2.8p25 1.4.0p8 1.5.0i1
Level Kleine Änderung
Klasse Sicherheitsfix
Kompatibilität Kompatibel - benötigt kein manuelles Eingreifen

A possible XSS issue has been fixed in the monitoring history views displaying the plugin output of hosts or services. In case a host or service problem is being acknowledged with HTML code in the acknowlegement comment, this HTML code was not being escaped properly when being displayed in the "plugin output" column.

Only authenticated users that are permitted to acknowledge host or service problems could trigger this issue.

Zur Liste aller Werks