Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper validation for URL parameters before reading the files.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NZabbix Web Service Report Generation
APPZabbix6.0.0 – 6.0.116.2.0 – 6.2.5Zabbix Agent2
APPZabbix< 6.0.126.2.0 – 6.2.6 (bez)
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Powiązane podatności
CVE-2023-29453CRITICAL9.8PL ✓ten sam produkt
Wstrzyknięcie kodu JavaScript w szablonach Go w Zabbix-Agent2
CVE-2022-22704CRITICAL9.8PL ✓ten sam produkt
Privilege escalation do root w zabbix-agent2 na Alpine Linux
CVE-2023-32728MEDIUM4.6ten sam produkt
The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell com...
CVE-2022-23131CRITICAL9.1⚠ KEVPL ✓ten sam vendor
Zabbix SAML SSO — privilege escalation do konta administratora
CVE-2024-42327CRITICAL9.9PL ✓ten sam vendor
SQL Injection w Zabbix – podatność w klasie CUser umożliwia eskalację uprawnień