{"id":"CVE-2022-24565","details":"Checkmk \u003c=2.0.0p19 Fixed in 2.0.0p20 and Checkmk \u003c=1.6.0p27 Fixed in 1.6.0p28 are affected by a Cross Site Scripting (XSS) vulnerability. The Alias of a site was not properly escaped when shown as condition for notifications.","modified":"2026-08-12T03:51:42.097816183Z","published":"2022-02-22T11:03:39Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24565.json"},"references":[{"type":"WEB","url":"https://checkmk.com/werk/13716"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24565.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24565"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/checkmk/checkmk","events":[{"introduced":"d5ccd5ecc956e665aca80f3c486f7fa46f409424"},{"last_affected":"484ded389cf62414abc10f16894abed01da8e4d2"}],"database_specific":{"source":"CPE_STRING","cpe":["cpe:2.3:a:checkmk:checkmk:1.6.0:-:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:b1:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p1:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:b10:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p10:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:b12:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p12:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:b3:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:b4:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:b5:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:b9:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p11:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p13:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p14:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p15:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p16:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p19:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p2:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p20:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p21:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p22:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p23:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p24:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p25:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p26:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p27:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:-:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:b1:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:i1:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p1:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:b2:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:b3:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:b4:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:b5:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:b6:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:b7:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:b8:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p10:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p11:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p12:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p13:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p14:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p15:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p16:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p17:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p18:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p19:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.6.0-NA"},{"last_affected":"1.6.0-NA"},{"introduced":"1.6.0-b1"},{"last_affected":"1.6.0-b1"},{"introduced":"1.6.0-p1"},{"last_affected":"1.6.0-p1"},{"introduced":"1.6.0-b10"},{"last_affected":"1.6.0-b10"},{"introduced":"1.6.0-p10"},{"last_affected":"1.6.0-p10"},{"introduced":"1.6.0-b12"},{"last_affected":"1.6.0-b12"},{"introduced":"1.6.0-p12"},{"last_affected":"1.6.0-p12"},{"introduced":"1.6.0-b3"},{"last_affected":"1.6.0-b3"},{"introduced":"1.6.0-b4"},{"last_affected":"1.6.0-b4"},{"introduced":"1.6.0-b5"},{"last_affected":"1.6.0-b5"},{"introduced":"1.6.0-b9"},{"last_affected":"1.6.0-b9"},{"introduced":"1.6.0-p11"},{"last_affected":"1.6.0-p11"},{"introduced":"1.6.0-p13"},{"last_affected":"1.6.0-p13"},{"introduced":"1.6.0-p14"},{"last_affected":"1.6.0-p14"},{"introduced":"1.6.0-p15"},{"last_affected":"1.6.0-p15"},{"introduced":"1.6.0-p16"},{"last_affected":"1.6.0-p16"},{"introduced":"1.6.0-p19"},{"last_affected":"1.6.0-p19"},{"introduced":"1.6.0-p2"},{"last_affected":"1.6.0-p2"},{"introduced":"1.6.0-p20"},{"last_affected":"1.6.0-p20"},{"introduced":"1.6.0-p21"},{"last_affected":"1.6.0-p21"},{"introduced":"1.6.0-p22"},{"last_affected":"1.6.0-p22"},{"introduced":"1.6.0-p23"},{"last_affected":"1.6.0-p23"},{"introduced":"1.6.0-p24"},{"last_affected":"1.6.0-p24"},{"introduced":"1.6.0-p25"},{"last_affected":"1.6.0-p25"},{"introduced":"1.6.0-p26"},{"last_affected":"1.6.0-p26"},{"introduced":"1.6.0-p27"},{"last_affected":"1.6.0-p27"},{"introduced":"2.0.0-NA"},{"last_affected":"2.0.0-NA"},{"introduced":"2.0.0-b1"},{"last_affected":"2.0.0-b1"},{"introduced":"2.0.0-i1"},{"last_affected":"2.0.0-i1"},{"introduced":"2.0.0-p1"},{"last_affected":"2.0.0-p1"},{"introduced":"2.0.0-b2"},{"last_affected":"2.0.0-b2"},{"introduced":"2.0.0-b3"},{"last_affected":"2.0.0-b3"},{"introduced":"2.0.0-b4"},{"last_affected":"2.0.0-b4"},{"introduced":"2.0.0-b5"},{"last_affected":"2.0.0-b5"},{"introduced":"2.0.0-b6"},{"last_affected":"2.0.0-b6"},{"introduced":"2.0.0-b7"},{"last_affected":"2.0.0-b7"},{"introduced":"2.0.0-b8"},{"last_affected":"2.0.0-b8"},{"introduced":"2.0.0-p10"},{"last_affected":"2.0.0-p10"},{"introduced":"2.0.0-p11"},{"last_affected":"2.0.0-p11"},{"introduced":"2.0.0-p12"},{"last_affected":"2.0.0-p12"},{"introduced":"2.0.0-p13"},{"last_affected":"2.0.0-p13"},{"introduced":"2.0.0-p14"},{"last_affected":"2.0.0-p14"},{"introduced":"2.0.0-p15"},{"last_affected":"2.0.0-p15"},{"introduced":"2.0.0-p16"},{"last_affected":"2.0.0-p16"},{"introduced":"2.0.0-p17"},{"last_affected":"2.0.0-p17"},{"introduced":"2.0.0-p18"},{"last_affected":"2.0.0-p18"},{"introduced":"2.0.0-p19"},{"last_affected":"2.0.0-p19"}]}}],"versions":["1.6.0-NA","1.6.0-b1","1.6.0-b10","1.6.0-b12","1.6.0-b3","1.6.0-b4","1.6.0-b5","1.6.0-b9","1.6.0-p11","1.6.0-p13","1.6.0-p14","1.6.0-p15","1.6.0-p16","1.6.0-p19","1.6.0-p2","1.6.0-p20","1.6.0-p21","1.6.0-p22","1.6.0-p23","1.6.0-p24","1.6.0-p25","1.6.0-p26","1.6.0-p27","2.0.0-NA","2.0.0-b1","2.0.0-b2","2.0.0-b3","2.0.0-b4","2.0.0-b5","2.0.0-b6","2.0.0-b7","2.0.0-b8","2.0.0-p10","2.0.0-p11","2.0.0-p12","2.0.0-p13","2.0.0-p14","2.0.0-p15","2.0.0-p16","2.0.0-p17","2.0.0-p18","2.0.0-p19"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-24565.json"}}],"schema_version":"1.9.0"}