← Back

CVE-2023-29449

nvd nist
Published: Jul 13, 2023Modified: Nov 3, 2025

JSON object

Loading...
4.9
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.2 / Impact: 3.6
Source: NVD

Description

JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles (Admin and Superadmin). Administrative privileges should be typically granted to users who need to perform tasks that require more control over the system. The security risk is limited because not all users have this level of access.

Affected (13)

Products: Zabbix: Zabbix
1 product
Zabbix
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Zabbix
Up to 5.0.31
From 6.0.0 to 6.0.13
From 6.4.1 to 6.4.4
Version 6.4.0 alpha1
Version 6.4.0 beta1
Version 6.4.0 beta2
Version 6.4.0 beta3
Version 6.4.0 beta4
Version 6.4.0 beta5
Version 6.4.0 beta6
Version 6.4.0 rc2
Version 6.4.0 rc3
Version 6.4.0 rc4

References (3)

Source: security@zabbix.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.