[//]: # (werk v2)
# Livestatus injection in mknotifyd
key | value
---------- | ---
date | 2024-07-08T11:58:09+00:00
version | 2.4.0b1
class | security
edition | cee
component | notifications
level | 1
compatible | yes
Before this Werk a malicious notification sent via mknotifyd could allow an attacker to
send arbitrary livestatus commands.
With this Werk livestatus escaping was added to the relevant functions.
This issue was found during internal review.
*Affected Versions*:
* 2.3.0
* 2.2.0
* 2.1.0
* 2.0.0 (EOL)
*Vulnerability Management*:
We have rated the issue with a CVSS Score of 6.5 Medium
(`CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L`) and assigned `CVE-2024-6542`.