cbcvebase.
CVE-2023-29450
published 2023-07-13

CVE-2023-29450: JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or…

PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.26%
66.4th percentile
JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianzabbix< zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye)zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye)
zabbixzabbix<= 5.0.33
zabbixzabbix>= 0 < 1:5.0.44+dfsg-1+deb11u11:5.0.44+dfsg-1+deb11u1
zabbixzabbix>= 0 < 1:6.0.23+dfsg-11:6.0.23+dfsg-1
zabbixzabbix>= 0 < 1:6.0.23+dfsg-11:6.0.23+dfsg-1
zabbixzabbix5.0 – 5.0.31
zabbixzabbix6.0 – 6.0.13
zabbixzabbix6.0.0 – 6.0.15
zabbixzabbix6.2 – 6.2.7
zabbixzabbix6.4 – 6.4.0rc1
zabbixzabbix6.4.0 – 6.4.1
zabbixzabbix6.4.3 – 6.4.4

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_debian8.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.