Branch: refs/heads/2.1.0
Home: https://github.com/Checkmk/checkmk
Commit: 6cbdbae71e184fb51c8f34983af59b1af7d6198d
https://github.com/Checkmk/checkmk/commit/6cbdbae71e184fb51c8f34983af59b1af…
Author: Maximilian Wirtz <maximilian.wirtz(a)checkmk.com>
Date: 2023-11-15 (Wed, 15 Nov 2023)
Changed paths:
A .werks/16219
M cmk/utils/regex.py
M tests/unit/cmk/gui/test_valuespec.py
Log Message:
-----------
16219 SEC Limit length of Hostname
Prior to this Werk it was possible to create Hosts with arbitrary length.
Since Checkmk stores information in files which paths contain the hostname these path could exceed the allowed length leading to various errors to an extend that rendered the usage of parts of the GUI useless.
We found this vulnerability internally.
<b>Affected Versions</b>:
* 2.2.0
* 2.1.0
* 2.0.0
<b>Vulnerability Management</b>:
We have rated the issue with a CVSS Score of 2.7 (Low) with the following CVSS vector:
<tt>CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L</tt>.
We assigned CVE-2023-23549 to this vulnerability.
<b>Changes</b>:
This Werk adds a maximum length of 253 characters for the hostname.
CMK-15105
Change-Id: I4be4745ede4220d05f4ff01d51aa6252dc9a1b57
Branch: refs/heads/2.2.0
Home: https://github.com/Checkmk/checkmk
Commit: 666306b569f16ed2b836a21e1f921f5f1961b50b
https://github.com/Checkmk/checkmk/commit/666306b569f16ed2b836a21e1f921f5f1…
Author: gradecke <gerdradecke(a)gmx.de>
Date: 2023-11-15 (Wed, 15 Nov 2023)
Changed paths:
A .werks/16288
M cmk/gui/wato/pages/audit_log.py
Log Message:
-----------
16288 audit log: Add options to hide object and object type
This werk introduces the option to toggle the 'object' and
'object type' columns in the audit log table.
Change-Id: I70bba2ba6a666609e9d0073f1fab8b1de6226430
Branch: refs/heads/master
Home: https://github.com/Checkmk/checkmk
Commit: c0ad73102c46a1ee4b92415c731593d7da3513d6
https://github.com/Checkmk/checkmk/commit/c0ad73102c46a1ee4b92415c731593d7d…
Author: gradecke <gerdradecke(a)gmx.de>
Date: 2023-11-15 (Wed, 15 Nov 2023)
Changed paths:
A .werks/16288
M cmk/gui/wato/pages/audit_log.py
Log Message:
-----------
16288 audit log: Add options to hide object and object type
This werk introduces the option to toggle the 'object' and
'object type' columns in the audit log table.
Change-Id: I70bba2ba6a666609e9d0073f1fab8b1de6226430
Branch: refs/heads/2.2.0
Home: https://github.com/Checkmk/checkmk
Commit: bb00feabd2621df6d67a36f8065fb9509c4c5456
https://github.com/Checkmk/checkmk/commit/bb00feabd2621df6d67a36f8065fb9509…
Author: Andreas Boesl <andreas.boesl(a)checkmk.com>
Date: 2023-11-15 (Wed, 15 Nov 2023)
Changed paths:
A .werks/14217
M cmk/base/config.py
Log Message:
-----------
14217 FIX No longer sporadically report stale services which are based on piggyback data
If the check interval of a host was greater than 1 minute, any of its reported piggyback data
was at risk of being ignored by the target host because of being too old.
Change-Id: I2462500e33e08ba04af8ea8f9969141c25c0da03