CVE-2023-29450
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
13/07/2023
Last modified:
03/11/2025
Description
JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data.
Impact
Base Score 3.x
8.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* | 5.0.33 (including) | |
| cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* | 6.0.0 (including) | 6.0.15 (including) |
| cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* | 6.4.0 (including) | 6.4.1 (including) |
| cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* | 6.4.3 (including) | 6.4.4 (including) |
To consult the complete list of CPE names with products and versions, see this page



