Logo
vulnerabilityCVE-2023-29449
Name
CVE-2023-29449
Source
NVD ( link)Debian ( link)
Description
JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles (Admin and Superadmin). Administrative privileges should be typically granted to users who need to perform tasks that require more control over the system. The security risk is limited because not all users have this level of access.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
zabbix
Patched

Vulnerability Ratings#


5.9
CVSSv31
4.9
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
7.2.13
Not Affected
buildroot
master
7.2.13
Not Affected
openwrt
master
7.0.26-r1
Not Affected
openwrt
openwrt-25.12
7.0.25-r1
Not Affected
yocto
master
7.0.24
Not Affected
yocto
scarthgap
6.2.9
Not Affected

Resolved with patches#


zabbix (yocto:kirkstone)

#
Title
Author
Resolve
1
.......PS. [DEV-2387] added new limits for JS objects
Dmitrijs Goloscapovs <dmitrijs.goloscapovs@zabbix.com>
CVE-2023-29449