We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-29449

Limited control of resource utilization in JS preprocessing



AssignerZabbix
Reserved2023-04-06
Published2023-07-13
Updated2024-10-22

Description

JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles (Admin and Superadmin). Administrative privileges should be typically granted to users who need to perform tasks that require more control over the system. The security risk is limited because not all users have this level of access.



MEDIUM: 5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Product status

Default status
unaffected

4.4.4
affected

5.0.0alpha1
affected

5.2.0alpha1
affected

5.4.0alpha1
affected

6.0.0alpha1
affected

6.2.0alpha1
affected

6.4.0alpha1
affected

References

https://support.zabbix.com/browse/ZBX-22589

cve.org CVE-2023-29449

nvd.nist.gov CVE-2023-29449

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2023-29449
Subscribe to our newsletter to learn more about our work.