MEDIUM🇵🇱 Wersja polska

CVE-2022-46768

CVSS 5.9v3.1pub. 2022-12-15upd. 2024-11-21

Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper validation for URL parameters before reading the files.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Zabbix Web Service Report Generation

    APP
    Zabbix
    6.0.0 – 6.0.116.2.0 – 6.2.5
  • Zabbix Agent2

    APP
    Zabbix
    < 6.0.126.2.0 – 6.2.6 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-29453CRITICAL9.8PL ✓same product

Wstrzyknięcie kodu JavaScript w szablonach Go w Zabbix-Agent2

CVE-2022-22704CRITICAL9.8PL ✓same product

Privilege escalation do root w zabbix-agent2 na Alpine Linux

CVE-2023-32728MEDIUM4.6same product

The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell com...

CVE-2022-23131CRITICAL9.1⚠ KEVPL ✓same vendor

Zabbix SAML SSO — privilege escalation do konta administratora

CVE-2024-42327CRITICAL9.9PL ✓same vendor

SQL Injection w Zabbix – podatność w klasie CUser umożliwia eskalację uprawnień