yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2023-29450
Component Overview
Vulnerability Overview
Name
CVE-2023-29450
Source
NVD (
link
)
Debian (
link
)
Description
JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data.
CWEs
CWE-200
CWE-552
Published Date
Jul 13, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://support.zabbix.com/browse/ZBX-22588
Vendor Advisory
https://support.zabbix.com/browse/ZBX-22588
Vendor Advisory
Analysis
#
Affected Component
Analysis
zabbix
Patched
Vulnerability Ratings
#
8.5
CVSSv31
7.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
zabbix
buildroot
2025.02.x
7.2.13
Not Affected
zabbix
buildroot
master
7.2.13
Not Affected
zabbix
openwrt
master
7.0.26-r1
Not Affected
zabbix
openwrt
openwrt-25.12
7.0.25-r1
Not Affected
zabbix
yocto
master
7.0.24
Not Affected
zabbix
yocto
scarthgap
6.2.9
Not Affected
Resolved with patches
#
zabbix (yocto:kirkstone)
#
Title
Author
Resolve
1
...G...PS. [DEV-2429] fixed unauthorised file system access
Vladislavs Sokurenko <vladislavs.sokurenko@zabbix.com>
CVE-2023-29450