Описание
A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
zabbix | fixed | 1:7.0.9+dfsg-1 | package | |
zabbix | not-affected | bookworm | package | |
zabbix | not-affected | bullseye | package |
Примечания
https://support.zabbix.com/browse/ZBX-26257
Fixed by: https://github.com/zabbix/zabbix/commit/529eec6957abff2f687c39219fa7a4a739d094c1 (7.0.8rc2)
"groupBy" feature introduced with https://github.com/zabbix/zabbix/commit/8a4e40ca6ff3b6be5c4144aaabf25cba315f5f4c (7.0.0alpha3)
Связанные уязвимости
A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter.
A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter.
A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter.