MEDIUM🇬🇧 English

CVE-2022-46768

CVSS 5.9v3.1pub. 2022-12-15upd. 2024-11-21

Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper validation for URL parameters before reading the files.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Zabbix Web Service Report Generation

    APP
    Zabbix
    6.0.0 – 6.0.116.2.0 – 6.2.5
  • Zabbix Agent2

    APP
    Zabbix
    < 6.0.126.2.0 – 6.2.6 (bez)
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2023-29453CRITICAL9.8PL ✓ten sam produkt

Wstrzyknięcie kodu JavaScript w szablonach Go w Zabbix-Agent2

CVE-2022-22704CRITICAL9.8PL ✓ten sam produkt

Privilege escalation do root w zabbix-agent2 na Alpine Linux

CVE-2023-32728MEDIUM4.6ten sam produkt

The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell com...

CVE-2022-23131CRITICAL9.1⚠ KEVPL ✓ten sam vendor

Zabbix SAML SSO — privilege escalation do konta administratora

CVE-2024-42327CRITICAL9.9PL ✓ten sam vendor

SQL Injection w Zabbix – podatność w klasie CUser umożliwia eskalację uprawnień