UBUNTU-CVE-2017-9781
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-9781
UBUNTU-CVE-2017-9781
Summary:
Details: A cross site scripting (XSS) vulnerability exists in Check_MK versions 1.4.0x prior to 1.4.0p6, allowing an unauthenticated remote attacker to inject arbitrary HTML or JavaScript via the _username parameter when attempting authentication to webapi.py, which is returned unencoded with content type text/html.
References: https://ubuntu.com/security/CVE-2017-9781, http://git.mathias-kettner.de/git/?p=check_mk.git;a=blob;f=.werks/4757;hb=c248f0b6ff7b15ced9f07a3df8a80fad656ea5b1, https://ubuntu.com/security/notices/USN-5527-1, https://www.cve.org/CVERecord?id=CVE-2017-9781, https://ubuntu.com/security/notices/USN-5527-2
Affected packages
Package
Name: check-mk
Purl: pkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
