CVE-2023-29449 — Uncontrolled Resource Consumption in Zabbix
Severity
4.9MEDIUMNVD
EPSS
0.9%
top 24.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 13
Description
JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles (Admin and Superadmin). Administrative privileges should be typically granted to users who need to perform tasks that require more control over the system. The security risk is limited because not all users have this level of access.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 1.2 | Impact: 3.6
Affected Packages4 packages
🔴Vulnerability Details
2📋Vendor Advisories
1Debian▶
CVE-2023-29449: zabbix - JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU...↗2023