CVE-2022-46768
Summary
| CVE | CVE-2022-46768 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-15 07:15:00 UTC |
| Updated | 2022-12-19 15:23:00 UTC |
| Description | Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper validation for URL parameters before reading the files. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [ZBX-22087] Zabbix Web Service Report Generation External Control of File Name Information Disclosure Vulnerability (CVE-2022-46768) - ZABBIX SUPPORT |
CONFIRM |
support.zabbix.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Trend Micro ZDI
Legacy QID Mappings
- 182229 Debian Security Update for zabbix (CVE-2022-46768)