Werk #6618: Fixed missing CSRF protection for host diagnostic AJAX calls

Komponente Setup
Titel Fixed missing CSRF protection for host diagnostic AJAX calls
Datum 17.09.2018
Checkmk Edition Checkmk Raw (CRE)
Checkmk-Version 1.4.0p36 1.5.0p5 1.6.0b1
Level Kleine Änderung
Klasse Sicherheitsfix
Kompatibilität Kompatibel - benötigt kein manuelles Eingreifen

The AJAX calls used by the host diagnostic page were not correctly using CSRF tokens to protect logged in users against malicious links that could trigger actions.

Zur Liste aller Werks