Описание
Security update for zabbix
This update for zabbix fixes the following issues:
- CVE-2024-22119: Fixed ability to run XSS in graph item names (bsc#1219775).
Список пакетов
SUSE Linux Enterprise Server 12 SP5
zabbix-agent-4.0.12-4.27.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
zabbix-agent-4.0.12-4.27.1
Ссылки
- Link for SUSE-SU-2024:0862-1
- E-Mail link for SUSE-SU-2024:0862-1
- SUSE Security Ratings
- SUSE Bug 1219775
- SUSE CVE CVE-2024-22119 page
Описание
The cause of vulnerability is improper validation of form input field "Name" on Graph page in Items section.
Затронутые продукты
SUSE Linux Enterprise Server 12 SP5:zabbix-agent-4.0.12-4.27.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5:zabbix-agent-4.0.12-4.27.1
Ссылки
- CVE-2024-22119
- SUSE Bug 1219775