CVE-2023-29450
published 2023-07-13CVE-2023-29450: JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.26%
66.4th percentile
JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zabbix | < zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye) | zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye) |
| zabbix | zabbix | <= 5.0.33 | — |
| zabbix | zabbix | >= 0 < 1:5.0.44+dfsg-1+deb11u1 | 1:5.0.44+dfsg-1+deb11u1 |
| zabbix | zabbix | >= 0 < 1:6.0.23+dfsg-1 | 1:6.0.23+dfsg-1 |
| zabbix | zabbix | >= 0 < 1:6.0.23+dfsg-1 | 1:6.0.23+dfsg-1 |
| zabbix | zabbix | 5.0 – 5.0.31 | — |
| zabbix | zabbix | 6.0 – 6.0.13 | — |
| zabbix | zabbix | 6.0.0 – 6.0.15 | — |
| zabbix | zabbix | 6.2 – 6.2.7 | — |
| zabbix | zabbix | 6.4 – 6.4.0rc1 | — |
| zabbix | zabbix | 6.4.0 – 6.4.1 | — |
| zabbix | zabbix | 6.4.3 – 6.4.4 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_debian8.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2023-29450: zabbix - JavaScript pre-processing can be used by the attacker to gain access to the file...
vendor_debian·2023·CVSS 8.5
CVE-2023-29450 [HIGH] CVE-2023-29450: zabbix - JavaScript pre-processing can be used by the attacker to gain access to the file...
JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data.
Scope: local
bookworm: open
bullseye: resolved (fixed in 1:5.0.44+dfsg-1+deb11u1)
forky: resolved (fixed in 1:6.0.23+dfsg-1)
sid: resolved (fixed in 1:6.0.23+dfsg-1)
trixie: resolved (fixed in 1:6.0.23+dfsg-1)
GHSA
GHSA-hfrc-jq43-4m6c: JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Se
ghsa_unreviewed·2023-07-13
CVE-2023-29450 [HIGH] CWE-200 GHSA-hfrc-jq43-4m6c: JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Se
JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data.
OSV
CVE-2023-29450: JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Se
osv·2023-07-13·CVSS 7.5
CVE-2023-29450 [HIGH] CVE-2023-29450: JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Se
JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-07-13
Published