Описание
A flaw was found in Zabbix. An authenticated administrator can exploit this vulnerability by creating specially crafted JavaScript scripts within preprocessing or script items. This can lead to a denial of service (DoS) by crashing the Zabbix server or proxy.
Отчет
Zabbix is not shipped in any Red Hat product. This flaw affects community packages in Fedora and EPEL only.
Меры по смягчению последствий
Restrict administrative access to trusted users only. Review and audit JavaScript preprocessing and script items configured on the Zabbix server.
Дополнительная информация
Статус:
EPSS
2.7 Low
CVSS3
Связанные уязвимости
(An authenticated administrator is able to crash Zabbix server or proxy ...)
An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scripts, leading to potential denial of service.
An authenticated administrator is able to crash Zabbix server or proxy ...
An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scripts, leading to potential denial of service.
EPSS
2.7 Low
CVSS3