Описание
Security update for zabbix
This update for zabbix fixes the following issues:
- CVE-2023-29450: Fixed unauthorized file system access in JS preprocessing (bsc#1213307).
Список пакетов
SUSE Linux Enterprise Server 12 SP5
zabbix-agent-4.0.12-4.24.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
zabbix-agent-4.0.12-4.24.1
Ссылки
- Link for SUSE-SU-2023:3029-1
- E-Mail link for SUSE-SU-2023:3029-1
- SUSE Security Ratings
- SUSE Bug 1213307
- SUSE CVE CVE-2023-29450 page
Описание
JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data.
Затронутые продукты
SUSE Linux Enterprise Server 12 SP5:zabbix-agent-4.0.12-4.24.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5:zabbix-agent-4.0.12-4.24.1
Ссылки
- CVE-2023-29450
- SUSE Bug 1213307