CVE-2023-29449

JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles (Admin and Superadmin). Administrative privileges should be typically granted to users who need to perform tasks that require more control over the system. The security risk is limited because not all users have this level of access.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:6.4.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:6.4.0:beta1:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:6.4.0:beta2:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:6.4.0:beta3:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:6.4.0:beta4:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:6.4.0:beta5:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:6.4.0:beta6:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:6.4.0:rc2:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:6.4.0:rc3:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:6.4.0:rc4:*:*:*:*:*:*

History

21 Nov 2024, 07:57

Type Values Removed Values Added
References () https://support.zabbix.com/browse/ZBX-22589 - Vendor Advisory () https://support.zabbix.com/browse/ZBX-22589 - Vendor Advisory
CVSS v2 : unknown
v3 : 4.9
v2 : unknown
v3 : 5.9

25 Jul 2023, 14:54

Type Values Removed Values Added
CWE CWE-770
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.9
First Time Zabbix zabbix
Zabbix
References (MISC) https://support.zabbix.com/browse/ZBX-22589 - (MISC) https://support.zabbix.com/browse/ZBX-22589 - Vendor Advisory
CPE cpe:2.3:a:zabbix:zabbix:6.4.0:beta1:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:6.4.0:beta6:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:6.4.0:rc3:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:6.4.0:beta5:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:6.4.0:rc2:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:6.4.0:beta2:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:6.4.0:beta4:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:6.4.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:6.4.0:beta3:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:6.4.0:rc4:*:*:*:*:*:*

13 Jul 2023, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-13 09:15

Updated : 2024-11-21 07:57


NVD link : CVE-2023-29449

Mitre link : CVE-2023-29449

CVE.ORG link : CVE-2023-29449


JSON object : View

Products Affected

zabbix

  • zabbix
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-770

Allocation of Resources Without Limits or Throttling