We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-29449

Limited control of resource utilization in JS preprocessing



Description

JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles (Admin and Superadmin). Administrative privileges should be typically granted to users who need to perform tasks that require more control over the system. The security risk is limited because not all users have this level of access.

Reserved 2023-04-06 | Published 2023-07-13 | Updated 2024-10-22 | Assigner Zabbix


MEDIUM: 5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-400 Uncontrolled Resource Consumption

Product status

Default status
unaffected

4.4.4
affected

5.0.0alpha1
affected

5.2.0alpha1
affected

5.4.0alpha1
affected

6.0.0alpha1
affected

6.2.0alpha1
affected

6.4.0alpha1
affected

References

support.zabbix.com/browse/ZBX-22589

cve.org (CVE-2023-29449)

nvd.nist.gov (CVE-2023-29449)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2023-29449

Support options

Helpdesk Chat, Email, Knowledgebase
Telegram Chat
Subscribe to our newsletter to learn more about our work.