PT-2023-7987 · Zabbix+4 · Zabbix+4

Alexander Vladishev

·

Published

2023-02-23

·

Updated

2024-12-10

·

CVE-2023-29450

CVSS v3.1

8.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zabbix (affected versions not specified)
Description The issue is related to the use of files and directories accessible to external parties, potentially allowing a remote attacker to gain read-only access to the file system on behalf of the user "zabbix" on the Zabbix Server or Zabbix Proxy. This could lead to unauthorized access to sensitive data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-6268
BDU:2023-09101
CVE-2023-29450
DLA-3538-1
DLA-3538-2
DLA-3909-1
ROSA-SA-2024-2539
SUSE-SU-2023:3029-1
SUSE-SU-2023_3029-1

Affected Products

Alt Linux
Astra Linux
Debian
Suse
Zabbix