PT-2023-7987 · Zabbix+4 · Zabbix+4

Alexander Vladishev

·

Publicado

2023-02-23

·

Atualizado

2024-12-10

·

CVE-2023-29450

CVSS v3.1

8.5

Alta

VetorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zabbix (affected versions not specified)
Description The issue is related to the use of files and directories accessible to external parties, potentially allowing a remote attacker to gain read-only access to the file system on behalf of the user "zabbix" on the Zabbix Server or Zabbix Proxy. This could lead to unauthorized access to sensitive data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Files Accessible to External Parties

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-6268
BDU:2023-09101
CVE-2023-29450
DLA-3538-1
DLA-3538-2
DLA-3909-1
ROSA-SA-2024-2539
SUSE-SU-2023:3029-1
SUSE-SU-2023_3029-1

Produtos afetados

Alt Linux
Astra Linux
Debian
Suse
Zabbix