Werk #14509: add authentication to REST API documentation

Component REST API
Title add authentication to REST API documentation
Date Sep 27, 2022
Checkmk Editon Checkmk Raw (CRE)
Checkmk Version 2.2.0i1 2.1.0p14 2.0.0p30
Level Trivial Change
Class Security Fix
Compatibility Compatible - no manual interaction needed

It was previously not required to be authenticated to access the site's REST API documentation.

Because custom user tags and comments may appear in the automatically generated documentation, this would represent an "information leak". Therefore, from this Werk onwards, the site's REST API documentation is only allowed to be accessed by logged in users.

Vulnerability Management: We have rated the issue with a CVSS Score of 5.3 (Medium) with the following CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N. A CVE has been requested

To the list of all Werks