Agent 2 package are built with Go version affected by CVE-2023-24538
CVE-2023-29453

9.8CRITICAL

Key Information:

Vendor

Zabbix

Status
Vendor
CVE Published:
12 October 2023

What is CVE-2023-29453?

A vulnerability exists in Zabbix Server that improperly handles backticks in JavaScript template literals, which can lead to JavaScript code injection through unintended template actions. This flaw emerges when Go template actions are embedded within JavaScript, enabling attackers to manipulate script execution. With the release of Go 1.21 and the implementation of protective measures, such injections are prevented by returning an error when such templates are detected. Users are advised to review their configurations, especially if they previously relied on the behavior that allowed these actions, as it can be restored via specific debugging flags with caution.

Affected Version(s)

Zabbix 5.0.0 <= 5.0.34

Zabbix 6.0.0 <= 6.0.17

Zabbix 6.4.0 <= 6.4.2

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.