Описание
Security update for zabbix
This update for zabbix fixes the following issues:
Updated to latest release 4.0.47, this version fixes CVE-2023-29454 (boo#1213338):
- New Features and Improvements
- ZBXNEXT-7694 Added 'utf8mb3' character set support for MySQL database
- ZBX-20946 Enabled Bulgarian, Chinese (zh_TW), German, Greek, Indonesian, Romanian, Spanish and Vietnamese languages in frontend
- Bug Fixes
- ZBX-22987 Fixed inefficient URL schema validation
- ZBX-22688 Fixed AlertScriptPath not allowing links
- ZBX-22386 Fixed encoding of HTML entities in the user interface
- ZBX-22858 Fixed xss vulnerability in graph item properties
- ZBX-22859 Fixed validation of input parameters in action configuration form
- ZBX-22622 Fixed alert script path validation
- ZBX-22520 Fixed versions of integrations
- ZBX-22026 Fixed SNMP agent item going to unsupported state on NULL result
- ZBX-22050 Fixed spoofing X-Forwarded-For request header allowing to access Zabbix frontend in maintenance mode
- ZBX-21416 Fixed check now not working on calculated items, aggregate checks and some internal items
- ZBX-21449 Fixed accessibility attributes
- ZBX-21306 Fixed xss in discovery rules
- ZBX-21305 Fixed xss in graph
- ZBX-20600 Fixed vmware hv.datastore.latency item when multiple datastores with duplicate name
- ZBX-20844 Fixed external check becoming unsupported when Zabbix server or Zabbix proxy is stopped
- ZBX-19789 Added SourceIP support to ldap simple checks
- ZBX-20680 Fixed reflected XSS issues
- ZBX-20387 Fixed default language of the setup routine for logged in superadmin users
- ZBX-19652 Fixed JavaScript syntax for Internet Explorer 11 compatibility
Список пакетов
SUSE Package Hub 15 SP4
zabbix-agent-4.0.47-bp155.3.3.1
zabbix-java-gateway-4.0.47-bp155.3.3.1
zabbix-phpfrontend-4.0.47-bp155.3.3.1
zabbix-proxy-4.0.47-bp155.3.3.1
zabbix-proxy-mysql-4.0.47-bp155.3.3.1
zabbix-proxy-postgresql-4.0.47-bp155.3.3.1
zabbix-proxy-sqlite-4.0.47-bp155.3.3.1
zabbix-server-4.0.47-bp155.3.3.1
zabbix-server-mysql-4.0.47-bp155.3.3.1
zabbix-server-postgresql-4.0.47-bp155.3.3.1
SUSE Package Hub 15 SP5
zabbix-agent-4.0.47-bp155.3.3.1
zabbix-java-gateway-4.0.47-bp155.3.3.1
zabbix-phpfrontend-4.0.47-bp155.3.3.1
zabbix-proxy-4.0.47-bp155.3.3.1
zabbix-proxy-mysql-4.0.47-bp155.3.3.1
zabbix-proxy-postgresql-4.0.47-bp155.3.3.1
zabbix-proxy-sqlite-4.0.47-bp155.3.3.1
zabbix-server-4.0.47-bp155.3.3.1
zabbix-server-mysql-4.0.47-bp155.3.3.1
zabbix-server-postgresql-4.0.47-bp155.3.3.1
openSUSE Leap 15.4
zabbix-agent-4.0.47-bp155.3.3.1
zabbix-java-gateway-4.0.47-bp155.3.3.1
zabbix-phpfrontend-4.0.47-bp155.3.3.1
zabbix-proxy-4.0.47-bp155.3.3.1
zabbix-proxy-mysql-4.0.47-bp155.3.3.1
zabbix-proxy-postgresql-4.0.47-bp155.3.3.1
zabbix-proxy-sqlite-4.0.47-bp155.3.3.1
zabbix-server-4.0.47-bp155.3.3.1
zabbix-server-mysql-4.0.47-bp155.3.3.1
zabbix-server-postgresql-4.0.47-bp155.3.3.1
openSUSE Leap 15.5
zabbix-agent-4.0.47-bp155.3.3.1
zabbix-java-gateway-4.0.47-bp155.3.3.1
zabbix-phpfrontend-4.0.47-bp155.3.3.1
zabbix-proxy-4.0.47-bp155.3.3.1
zabbix-proxy-mysql-4.0.47-bp155.3.3.1
zabbix-proxy-postgresql-4.0.47-bp155.3.3.1
zabbix-proxy-sqlite-4.0.47-bp155.3.3.1
zabbix-server-4.0.47-bp155.3.3.1
zabbix-server-mysql-4.0.47-bp155.3.3.1
zabbix-server-postgresql-4.0.47-bp155.3.3.1
Ссылки
- E-Mail link for openSUSE-SU-2023:0191-1
- SUSE Security Ratings
- SUSE Bug 1213338
- SUSE CVE CVE-2023-29454 page
Описание
Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., in a database or server-side text files), and finally, the application unintentionally executes the payload for every victim visiting its web pages.
Затронутые продукты
SUSE Package Hub 15 SP4:zabbix-agent-4.0.47-bp155.3.3.1
SUSE Package Hub 15 SP4:zabbix-java-gateway-4.0.47-bp155.3.3.1
SUSE Package Hub 15 SP4:zabbix-phpfrontend-4.0.47-bp155.3.3.1
SUSE Package Hub 15 SP4:zabbix-proxy-4.0.47-bp155.3.3.1
Ссылки
- CVE-2023-29454
- SUSE Bug 1213338