CVE-2014-5338

Publication date 22 August 2014

Last updated 24 July 2024


Ubuntu priority

Description

Multiple cross-site scripting (XSS) vulnerabilities in the multisite component in Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors to the (1) render_status_icons function in htmllib.py or (2) ajax_action function in actions.py.

Read the notes from the security team

Status

Package Ubuntu Release Status
check-mk 14.04 LTS trusty Not in release
12.04 LTS precise
Not affected
10.04 LTS lucid Not in release

Notes


jdstrand

per Debian, code not present in 2.3


Access our resources on patching vulnerabilities