Bug 2251871 (CVE-2023-32723) - CVE-2023-32723 zabbix: inefficient permission check in class CControllerAuthenticationUpdate
Summary: CVE-2023-32723 zabbix: inefficient permission check in class CControllerAuthe...
Keywords:
Status: NEW
Alias: CVE-2023-32723
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2251872
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-11-28 06:31 UTC by Marian Rehak
Modified: 2023-11-28 06:32 UTC (History)
0 users

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Marian Rehak 2023-11-28 06:31:59 UTC
This vulnerability is causing unauthorized Server-Side Request Forgery (SSRF) in Zabbix Frontend. Attack involves an attacker abusing server functionality to access or modify resources. The attacker targets an application that supports data reads or imports from URLs.

Reference:

https://support.zabbix.com/browse/ZBX-23230

Comment 1 Marian Rehak 2023-11-28 06:32:12 UTC
Created zabbix tracking bugs for this issue:

Affects: fedora-all [bug 2251872]


Note You need to log in before you can comment on or make changes to this bug.