CVE-2023-32725
18.12.2023, 10:15
The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.Enginsight
Vendor | Product | Version |
---|---|---|
zabbix | zabbix_server | 6.0.0 ≤ 𝑥 ≤ 6.0.21 |
zabbix | zabbix_server | 6.4.0 ≤ 𝑥 ≤ 6.4.6 |
zabbix | zabbix_server | 7.0.0:alpha1 |
zabbix | zabbix_server | 7.0.0:alpha2 |
zabbix | zabbix_server | 7.0.0:alpha3 |
zabbix | frontend | 6.0.0 ≤ 𝑥 ≤ 6.0.21 |
zabbix | frontend | 6.4.0 ≤ 𝑥 ≤ 6.4.6 |
zabbix | frontend | 7.0.0:alpha1 |
zabbix | frontend | 7.0.0:alpha2 |
zabbix | frontend | 7.0.0:alpha3 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases