Werk #11085: Icon upload: Add missing transaction validation
| Component | Setup | ||||
| Title | Icon upload: Add missing transaction validation | ||||
| Date | Jul 3, 2020 | ||||
| Level | Trivial Change | ||||
| Class | Security Fix | ||||
| Compatibility | Compatible - no manual interaction needed | ||||
| Checkmk versions & editions |
|
The transaction IDs (CSRF tokens) were not validated while processing the upload of icons. This alone is not a security hole, rather a lack of validation of this call.