CVE-2023-29449

JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles (Admin and Superadmin). Administrative privileges should be typically granted to users who need to perform tasks that require more control over the system. The security risk is limited because not all users have this level of access. 
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
ZabbixCNA
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 62%
VendorProductVersion
zabbixzabbix
𝑥
≤ 5.0.31
zabbixzabbix
6.0.0 ≤
𝑥
≤ 6.0.13
zabbixzabbix
6.4.1 ≤
𝑥
≤ 6.4.4
zabbixzabbix
6.4.0:alpha1
zabbixzabbix
6.4.0:beta1
zabbixzabbix
6.4.0:beta2
zabbixzabbix
6.4.0:beta3
zabbixzabbix
6.4.0:beta4
zabbixzabbix
6.4.0:beta5
zabbixzabbix
6.4.0:beta6
zabbixzabbix
6.4.0:rc2
zabbixzabbix
6.4.0:rc3
zabbixzabbix
6.4.0:rc4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
zabbix
bullseye
vulnerable
bookworm
no-dsa
buster
not-affected
bullseye (security)
1:5.0.45+dfsg-1+deb11u1
fixed
sid
1:7.0.6+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
zabbix
oracular
not-affected
noble
dne
mantic
not-affected
lunar
ignored
kinetic
ignored
jammy
needed
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
not-affected