CVE-2023-29450

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
13/07/2023
Last modified:
03/11/2025

Description

JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* 5.0.33 (including)
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* 6.0.0 (including) 6.0.15 (including)
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* 6.4.0 (including) 6.4.1 (including)
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* 6.4.3 (including) 6.4.4 (including)