Werk #3297: Fixes possible XSS in views sidebar snapin

Komponente User interface
Titel Fixes possible XSS in views sidebar snapin
Datum 21.03.2016
Checkmk Edition Checkmk Raw (CRE)
Checkmk-Version 1.2.8b8 1.4.0i1
Level Kleine Änderung
Klasse Sicherheitsfix
Kompatibilität Kompatibel - benötigt kein manuelles Eingreifen

Authenticated and permitted users could create views using a topic which might contains HTML code, for example script tags, that where executed when having the view listed in the views snapin.

Making the JS code be executed by other users is only possible with view publish permissions which normally only admin users have.

Zur Liste aller Werks