ZABBIX Server — свободная система мониторинга статусов разнообразных сервисов компьютерной сети, серверов и сетевого оборудования
Релизный цикл, информация об уязвимостях
График релизов
Количество 8
openSUSE-SU-2023:0419-1
Security update for zabbix
openSUSE-SU-2023:0418-1
Security update for zabbix
CVE-2023-32727
An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.
CVE-2023-32727
An attacker who has the privilege to configure Zabbix items can use fu ...
CVE-2023-32725
The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.
CVE-2023-32725
The website configured in the URL widget will receive a session cookie ...
CVE-2023-32727
An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.
CVE-2023-32725
The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
openSUSE-SU-2023:0419-1 Security update for zabbix | 0% Низкий | почти 2 года назад | ||
openSUSE-SU-2023:0418-1 Security update for zabbix | 0% Низкий | почти 2 года назад | ||
CVE-2023-32727 An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server. | CVSS3: 6.8 | 0% Низкий | почти 2 года назад | |
CVE-2023-32727 An attacker who has the privilege to configure Zabbix items can use fu ... | CVSS3: 6.8 | 0% Низкий | почти 2 года назад | |
CVE-2023-32725 The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user. | CVSS3: 9.6 | 0% Низкий | почти 2 года назад | |
CVE-2023-32725 The website configured in the URL widget will receive a session cookie ... | CVSS3: 9.6 | 0% Низкий | почти 2 года назад | |
CVE-2023-32727 An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server. | CVSS3: 6.8 | 0% Низкий | почти 2 года назад | |
CVE-2023-32725 The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user. | CVSS3: 9.6 | 0% Низкий | почти 2 года назад |
Уязвимостей на страницу