Branch: refs/heads/master
Home:
https://github.com/Checkmk/checkmk
Commit: 10d3062a3fb85a26d77bb4b33c445cbd4fbaaf59
https://github.com/Checkmk/checkmk/commit/10d3062a3fb85a26d77bb4b33c445cbd4…
Author: Maximilian Wirtz <maximilian.wirtz(a)checkmk.com>
Date: 2023-11-15 (Wed, 15 Nov 2023)
Changed paths:
A .werks/16219
M cmk/utils/regex.py
M tests/unit/cmk/gui/test_valuespec.py
Log Message:
-----------
16219 SEC Limit length of Hostname
Prior to this Werk it was possible to create Hosts with arbitrary length.
Since Checkmk stores information in files which paths contain the hostname these path
could exceed the allowed length leading to various errors to an extend that rendered the
usage of parts of the GUI useless.
We found this vulnerability internally.
<b>Affected Versions</b>:
* 2.2.0
* 2.1.0
* 2.0.0
<b>Vulnerability Management</b>:
We have rated the issue with a CVSS Score of 2.7 (Low) with the following CVSS vector:
<tt>CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L</tt>.
We assigned CVE-2023-23549 to this vulnerability.
<b>Changes</b>:
This Werk adds a maximum length of 253 characters for the hostname.
CMK-15105
Change-Id: I4be4745ede4220d05f4ff01d51aa6252dc9a1b57
Commit: d85257a7c8e1c5e95a37ef6c509bd1e9b7a9eb68
https://github.com/Checkmk/checkmk/commit/d85257a7c8e1c5e95a37ef6c509bd1e9b…
Author: Simon Jess <simon.jess(a)checkmk.com>
Date: 2023-11-15 (Wed, 15 Nov 2023)
Changed paths:
A packages/cmk-graphing/cmk/graphing/v1/_name.py
M packages/cmk-graphing/cmk/graphing/v1/graph.py
M packages/cmk-graphing/cmk/graphing/v1/metric.py
M packages/cmk-graphing/cmk/graphing/v1/perfometer.py
M packages/cmk-graphing/cmk/graphing/v1/translation.py
M packages/cmk-graphing/tests/test_graph.py
M packages/cmk-graphing/tests/test_metric.py
M packages/cmk-graphing/tests/test_perfometer.py
M packages/cmk-graphing/tests/test_translation.py
Log Message:
-----------
Introduce '*Name's
Change-Id: I8c21e8cb3243d68f23221d6dc6cdc0e2d1861225
Compare:
https://github.com/Checkmk/checkmk/compare/7dea93bf25e8...d85257a7c8e1