Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2023:0191-1

Опубликовано: 24 июл. 2023
Источник: suse-cvrf

Описание

Security update for zabbix

This update for zabbix fixes the following issues:

Updated to latest release 4.0.47, this version fixes CVE-2023-29454 (boo#1213338):

  • New Features and Improvements
    • ZBXNEXT-7694 Added 'utf8mb3' character set support for MySQL database
    • ZBX-20946 Enabled Bulgarian, Chinese (zh_TW), German, Greek, Indonesian, Romanian, Spanish and Vietnamese languages in frontend
  • Bug Fixes
    • ZBX-22987 Fixed inefficient URL schema validation
    • ZBX-22688 Fixed AlertScriptPath not allowing links
    • ZBX-22386 Fixed encoding of HTML entities in the user interface
    • ZBX-22858 Fixed xss vulnerability in graph item properties
    • ZBX-22859 Fixed validation of input parameters in action configuration form
    • ZBX-22622 Fixed alert script path validation
    • ZBX-22520 Fixed versions of integrations
    • ZBX-22026 Fixed SNMP agent item going to unsupported state on NULL result
    • ZBX-22050 Fixed spoofing X-Forwarded-For request header allowing to access Zabbix frontend in maintenance mode
    • ZBX-21416 Fixed check now not working on calculated items, aggregate checks and some internal items
    • ZBX-21449 Fixed accessibility attributes
    • ZBX-21306 Fixed xss in discovery rules
    • ZBX-21305 Fixed xss in graph
    • ZBX-20600 Fixed vmware hv.datastore.latency item when multiple datastores with duplicate name
    • ZBX-20844 Fixed external check becoming unsupported when Zabbix server or Zabbix proxy is stopped
    • ZBX-19789 Added SourceIP support to ldap simple checks
    • ZBX-20680 Fixed reflected XSS issues
    • ZBX-20387 Fixed default language of the setup routine for logged in superadmin users
    • ZBX-19652 Fixed JavaScript syntax for Internet Explorer 11 compatibility

Список пакетов

SUSE Package Hub 15 SP4
zabbix-agent-4.0.47-bp155.3.3.1
zabbix-java-gateway-4.0.47-bp155.3.3.1
zabbix-phpfrontend-4.0.47-bp155.3.3.1
zabbix-proxy-4.0.47-bp155.3.3.1
zabbix-proxy-mysql-4.0.47-bp155.3.3.1
zabbix-proxy-postgresql-4.0.47-bp155.3.3.1
zabbix-proxy-sqlite-4.0.47-bp155.3.3.1
zabbix-server-4.0.47-bp155.3.3.1
zabbix-server-mysql-4.0.47-bp155.3.3.1
zabbix-server-postgresql-4.0.47-bp155.3.3.1
SUSE Package Hub 15 SP5
zabbix-agent-4.0.47-bp155.3.3.1
zabbix-java-gateway-4.0.47-bp155.3.3.1
zabbix-phpfrontend-4.0.47-bp155.3.3.1
zabbix-proxy-4.0.47-bp155.3.3.1
zabbix-proxy-mysql-4.0.47-bp155.3.3.1
zabbix-proxy-postgresql-4.0.47-bp155.3.3.1
zabbix-proxy-sqlite-4.0.47-bp155.3.3.1
zabbix-server-4.0.47-bp155.3.3.1
zabbix-server-mysql-4.0.47-bp155.3.3.1
zabbix-server-postgresql-4.0.47-bp155.3.3.1
openSUSE Leap 15.4
zabbix-agent-4.0.47-bp155.3.3.1
zabbix-java-gateway-4.0.47-bp155.3.3.1
zabbix-phpfrontend-4.0.47-bp155.3.3.1
zabbix-proxy-4.0.47-bp155.3.3.1
zabbix-proxy-mysql-4.0.47-bp155.3.3.1
zabbix-proxy-postgresql-4.0.47-bp155.3.3.1
zabbix-proxy-sqlite-4.0.47-bp155.3.3.1
zabbix-server-4.0.47-bp155.3.3.1
zabbix-server-mysql-4.0.47-bp155.3.3.1
zabbix-server-postgresql-4.0.47-bp155.3.3.1
openSUSE Leap 15.5
zabbix-agent-4.0.47-bp155.3.3.1
zabbix-java-gateway-4.0.47-bp155.3.3.1
zabbix-phpfrontend-4.0.47-bp155.3.3.1
zabbix-proxy-4.0.47-bp155.3.3.1
zabbix-proxy-mysql-4.0.47-bp155.3.3.1
zabbix-proxy-postgresql-4.0.47-bp155.3.3.1
zabbix-proxy-sqlite-4.0.47-bp155.3.3.1
zabbix-server-4.0.47-bp155.3.3.1
zabbix-server-mysql-4.0.47-bp155.3.3.1
zabbix-server-postgresql-4.0.47-bp155.3.3.1

Описание

Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., in a database or server-side text files), and finally, the application unintentionally executes the payload for every victim visiting its web pages.


Затронутые продукты
SUSE Package Hub 15 SP4:zabbix-agent-4.0.47-bp155.3.3.1
SUSE Package Hub 15 SP4:zabbix-java-gateway-4.0.47-bp155.3.3.1
SUSE Package Hub 15 SP4:zabbix-phpfrontend-4.0.47-bp155.3.3.1
SUSE Package Hub 15 SP4:zabbix-proxy-4.0.47-bp155.3.3.1

Ссылки