CVE-2023-29449

EUVD-2023-33018
JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles (Admin and Superadmin). Administrative privileges should be typically granted to users who need to perform tasks that require more control over the system. The security risk is limited because not all users have this level of access. 
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
ZabbixCNA
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 72%
Affected Products (NVD)
VendorProductVersion
zabbixzabbix
𝑥
≤ 5.0.31
zabbixzabbix
6.0.0 ≤
𝑥
≤ 6.0.13
zabbixzabbix
6.4.1 ≤
𝑥
≤ 6.4.4
zabbixzabbix
6.4.0:alpha1
zabbixzabbix
6.4.0:beta1
zabbixzabbix
6.4.0:beta2
zabbixzabbix
6.4.0:beta3
zabbixzabbix
6.4.0:beta4
zabbixzabbix
6.4.0:beta5
zabbixzabbix
6.4.0:beta6
zabbixzabbix
6.4.0:rc2
zabbixzabbix
6.4.0:rc3
zabbixzabbix
6.4.0:rc4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
zabbix
bookworm
no-dsa
bullseye
vulnerable
bullseye (security)
1:5.0.45+dfsg-1+deb11u1
fixed
buster
not-affected
sid
1:7.0.6+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
zabbix
bionic
not-affected
focal
not-affected
jammy
needed
kinetic
ignored
lunar
ignored
mantic
not-affected
noble
dne
oracular
not-affected
trusty
not-affected
xenial
not-affected