QID 150700

Date Published: 2023-08-17

QID 150700: Zabbix Sensitive Information Disclosure Vulnerability (CVE-2023-29450)

Zabbix is an open-source software tool to monitor IT infrastructure such as networks, servers, virtual machines, and cloud services.

JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data.

Affected version:
Zabbix before version 5.0.34
Zabbix version from 6.0.0 to 6.0.16
Zabbix version from 6.4.0 to 6.4.1
Zabbix version from 6.4.3 to 6.4.4

QID Detection Logic (Unauthenticated):
This QID sends a HTTP POST request to "api_jsonrpc.php" endpoint and checks the response body to confirm if the host is running vulnerable version of Zabbix Server.

Successful exploitation of this vulnerability could allow an unauthorized attacker to gain Sensitive Information.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Customers are advised to upgrade Zabbix to new version to remediate this vulnerability. For more information please refer to ZBX-22588.

    Vendor References

    CVEs related to QID 150700

    Software Advisories
    Advisory ID Software Component Link
    ZBX-22588 URL Logo support.zabbix.com/browse/ZBX-22588