← Back

CVE-2022-46768

nvd nist
Published: Dec 15, 2022Modified: Nov 21, 2024

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper validation for URL parameters before reading the files.

Affected (4)

2 products
Web Service Report Generation
Zabbix Agent2
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Zabbix
From 6.0.0 to 6.0.11
From 6.2.0 to 6.2.5
Zabbix
Before 6.0.12
From 6.2.0 to 6.2.6

References (2)

Source: security@zabbix.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.