Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-22123

Опубликовано: 12 авг. 2024
Источник: debian
EPSS Низкий

Описание

Setting SMS media allows to set GSM modem file. Later this file is used as Linux device. But due everything is a file for Linux, it is possible to set another file, e.g. log file and zabbix_server will try to communicate with it as modem. As a result, log file will be broken with AT commands and small part for log file content will be leaked to UI.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zabbixfixed1:7.0.0+dfsg-1package

Примечания

  • https://support.zabbix.com/browse/ZBX-25013

  • https://github.com/zabbix/zabbix/commit/499ac935f60b38992488ff895c06da8bd80d95cc (7.0.x)

  • https://github.com/zabbix/zabbix/commit/eb64b83355dae7286821c5237f7ab83038c22367 (6.0.x)

  • https://github.com/zabbix/zabbix/commit/dcd875c22d0f3e5106e855d9f7e9ef7c51fae9aa (5.0.x)

EPSS

Процентиль: 57%
0.00355
Низкий

Связанные уязвимости

CVSS3: 2.7
ubuntu
около 1 года назад

Setting SMS media allows to set GSM modem file. Later this file is used as Linux device. But due everything is a file for Linux, it is possible to set another file, e.g. log file and zabbix_server will try to communicate with it as modem. As a result, log file will be broken with AT commands and small part for log file content will be leaked to UI.

CVSS3: 2.7
nvd
около 1 года назад

Setting SMS media allows to set GSM modem file. Later this file is used as Linux device. But due everything is a file for Linux, it is possible to set another file, e.g. log file and zabbix_server will try to communicate with it as modem. As a result, log file will be broken with AT commands and small part for log file content will be leaked to UI.

CVSS3: 2.7
github
около 1 года назад

Setting SMS media allows to set GSM modem file. Later this file is used as Linux device. But due everything is a file for Linux, it is possible to set another file, e.g. log file and zabbix_server will try to communicate with it as modem. As a result, log file will be broken with AT commands and small part for log file content will be leaked to UI.

CVSS3: 2.7
fstec
около 1 года назад

Уязвимость универсальной системы мониторинга Zabbix, связанная с неправильным контролем генерации кода, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.1
redos
около 1 года назад

Множественные уязвимости zabbix

EPSS

Процентиль: 57%
0.00355
Низкий