Werk #6609: Fixed possible XSS on SNMP MIB upload page

Komponente Setup
Titel Fixed possible XSS on SNMP MIB upload page
Datum 13.09.2018
Level Kleine Änderung
Klasse Sicherheitsfix
Kompatibilität Kompatibel - benötigt kein manuelles Eingreifen
Checkmk versions & editions
1.6.0b1 Checkmk Raw (CRE), Checkmk Enterprise (CEE), Checkmk MSP (CME)
1.5.0p5 Checkmk Raw (CRE), Checkmk Enterprise (CEE), Checkmk MSP (CME)
1.4.0p36 Checkmk Raw (CRE), Checkmk Enterprise (CEE), Checkmk MSP (CME)

Using MIB files with specific names it was possible to trigger an XSS on the MIB file administration page which only affected admin users.

Zur Liste aller Werks