CVE-2024-38857: Checkmk

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper neutralization of input in Checkmk before versions 2.3.0p8, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows attackers to craft malicious links that can facilitate phishing attacks.

Affected products

  • Checkmk Checkmk: up to and including 2.0.0; version 2.1.0 only; version 2.2.0 only; version 2.3.0 only

Published 2024-07-02. Last modified 2026-06-17.