Werk #17990: Potential livestatus injection in prediction graph page
| Component | User interface | ||||||||
| Title | Potential livestatus injection in prediction graph page | ||||||||
| Date | Mar 23, 2026 | ||||||||
| Level | Trivial Change | ||||||||
| Class | Security Fix | ||||||||
| Compatibility | Compatible - no manual interaction needed | ||||||||
| Checkmk versions & editions |
|
Prior to this fix, the prediction graph page did not properly sanitize the user-supplied service description value before interpolating it into Livestatus queries. This allowed an authenticated user to inject arbitrary Livestatus commands via a crafted service name parameter.
This issue was found during internal review.
Affected Versions:
- 2.5.0
- 2.4.0
- 2.3.0
Vulnerability Management:
We have rated the issue with a CVSS score of 5.3 (Medium) with the following CVSS vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N, and assigned CVE-2026-33457.