Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-29450

Опубликовано: 13 июл. 2023
Источник: ubuntu
Приоритет: medium
CVSS3: 8.5

Описание

JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

1:6.0.29+dfsg-1
esm-apps/bionic

not-affected

code not present
esm-apps/focal

not-affected

code not present
esm-apps/jammy

needed

esm-apps/xenial

not-affected

code not present
esm-infra-legacy/trusty

not-affected

code not present
focal

not-affected

code not present
jammy

needed

kinetic

ignored

end of life, was needs-triage

Показывать по

8.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.5
nvd
больше 2 лет назад

JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data.

CVSS3: 8.5
debian
больше 2 лет назад

JavaScript pre-processing can be used by the attacker to gain access t ...

suse-cvrf
больше 2 лет назад

Security update for zabbix

CVSS3: 8.5
github
больше 2 лет назад

JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data.

CVSS3: 7.5
fstec
почти 3 года назад

Уязвимость универсальной системы мониторинга Zabbix, связанная с использованием файлов и каталогов, доступных внешним сторонам, позволяющая нарушителю получить доступ к конфиденциальным данным

8.5 High

CVSS3