Werk #13067: Fix path traversal vulnerability

Component WATO
Title Fix path traversal vulnerability
Date Aug 16, 2021
Checkmk Editon Checkmk Raw (CRE)
Checkmk Version 2.1.0i1 2.0.0p10 1.6.0p26
Level Trivial Change
Class Security Fix
Compatibility Compatible - no manual interaction needed

An authenticated user was able to enumerate files ending with ".csv" on the filesystem, accessible to the siteuser.

To the list of all Werks