{"id":"CVE-2024-38858","summary":"Cross-site scripting in Robotmk logs view","details":"Improper neutralization of input in Checkmk before version 2.3.0p14 allows attackers to inject and run malicious scripts in the Robotmk logs view.","modified":"2026-08-12T03:51:48.392663406Z","published":"2024-09-02T09:16:40.902Z","database_specific":{"cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/38xxx/CVE-2024-38858.json","unresolved_ranges":[{"extracted_events":[{"introduced":"2.3.0"},{"fixed":"2.3.0p14"}],"source":"AFFECTED_FIELD"},{"extracted_events":[{"fixed":"2.3.0p14"}],"source":"DESCRIPTION"}],"cna_assigner":"Checkmk"},"references":[{"type":"WEB","url":"https://checkmk.com/werk/17232"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/38xxx/CVE-2024-38858.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-38858"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/checkmk/checkmk","events":[{"introduced":"0"},{"fixed":"779a2941a075e1461b45407f715176524414b994"},{"introduced":"779a2941a075e1461b45407f715176524414b994"},{"last_affected":"241e7e776b96d316693575e91023518e20e171be"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.3.0"},{"introduced":"2.3.0-NA"},{"last_affected":"2.3.0-NA"},{"introduced":"2.3.0-p1"},{"last_affected":"2.3.0-p1"},{"introduced":"2.3.0-p10"},{"last_affected":"2.3.0-p10"},{"introduced":"2.3.0-p11"},{"last_affected":"2.3.0-p11"},{"introduced":"2.3.0-p12"},{"last_affected":"2.3.0-p12"},{"introduced":"2.3.0-p13"},{"last_affected":"2.3.0-p13"},{"introduced":"2.3.0-p2"},{"last_affected":"2.3.0-p2"},{"introduced":"2.3.0-p3"},{"last_affected":"2.3.0-p3"},{"introduced":"2.3.0-p4"},{"last_affected":"2.3.0-p4"},{"introduced":"2.3.0-p5"},{"last_affected":"2.3.0-p5"},{"introduced":"2.3.0-p6"},{"last_affected":"2.3.0-p6"},{"introduced":"2.3.0-p7"},{"last_affected":"2.3.0-p7"},{"introduced":"2.3.0-p8"},{"last_affected":"2.3.0-p8"},{"introduced":"2.3.0-p9"},{"last_affected":"2.3.0-p9"}],"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.3.0:-:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.3.0:p1:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.3.0:p10:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.3.0:p11:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.3.0:p12:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.3.0:p13:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.3.0:p2:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.3.0:p3:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.3.0:p4:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.3.0:p5:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.3.0:p6:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.3.0:p7:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.3.0:p8:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.3.0:p9:*:*:*:*:*:*"]}}],"versions":["2.3.0-NA","2.3.0-p1","2.3.0-p10","2.3.0-p11","2.3.0-p12","2.3.0-p13","2.3.0-p2","2.3.0-p3","2.3.0-p4","2.3.0-p5","2.3.0-p6","2.3.0-p7","2.3.0-p8","2.3.0-p9","v2.3.0p9-rc1","v2.3.0p9","v2.3.0p8-rc1","v2.3.0p8","v2.3.0p7-rc1","v2.3.0p6-rc1","v2.3.0p6","v2.3.0p5-rc1","v2.3.0p5","v2.3.0p4-rc1","v2.3.0p4","v2.3.0p3-rc1","v2.3.0p2-rc1","v2.3.0p2","v2.3.0p1-rc1","v2.3.0p1","v2.3.0-rc2","v2.3.0-rc1","v2.3.0b6-rc1","v2.3.0b5-rc1","v2.3.0b5","v2.3.0b4-rc2","v2.3.0b4-rc1","v2.3.0b3-rc1","v2.3.0b3","v2.3.0b2-rc1","v2.3.0b2","v2.3.0b1-rc1","v2.3.0b1","v2.3.0b1-rc2","v2.0.0i1","v1.6.0b1","v1.5.0i3","v1.5.0i2","v1.5.0i1","v1.4.0i3","v1.4.0i2","v1.4.0i1","v1.2.5i6","v1.2.5i1","v1.2.3i6","v1.2.3i5","v1.2.3i4","v1.2.1i5","v1.2.0p1","v1.2.0b4","v1.2.0b3","v1.2.0b2","v1.1.13i3","v1.1.13i2","v1.1.11i3","v1.1.11i2","v1.1.11i1","v1.1.10","v1.1.10b2","v1.1.10b1","v1.1.9i9","v1.1.9i8","v1.1.9i7","v1.1.9i5","v1.1.9i4","v1.1.9i3","v1.1.9i1","v1.1.8","v1.1.8b3","v1.1.8b2","v1.1.8b1","v1.1.7i5","v1.1.7i4","v1.1.7i3","v1.1.7i2","v1.1.6","v1.1.6b2","v1.1.4","v1.1.3","v1.1.2","v1.1.0","1.1.0beta17"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-38858.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}