CVE-2023-29449Uncontrolled Resource Consumption in Zabbix

Severity
4.9MEDIUMNVD
EPSS
0.9%
top 24.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 13

Description

JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles (Admin and Superadmin). Administrative privileges should be typically granted to users who need to perform tasks that require more control over the system. The security risk is limited because not all users have this level of access.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 1.2 | Impact: 3.6

Affected Packages4 packages

debiandebian/zabbix< zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye)
Debianzabbix/zabbix< 1:5.0.44+dfsg-1+deb11u1+2
CVEListV5zabbix/zabbix4.4.44.4.*+6
NVDzabbix/zabbix6.0.06.0.13+3

🔴Vulnerability Details

2
GHSA
GHSA-7q7m-r84j-6pm2: JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization2023-07-13
OSV
CVE-2023-29449: JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization2023-07-13

📋Vendor Advisories

1
Debian
CVE-2023-29449: zabbix - JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU...2023