Showing 1 vulnerability on this page for zabbix-agent2

Signals CISA KEV Ransomware Nuclei
Zabbix vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Agent 2 package are built with Go version affected by CVE-2023-24538

Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the action can be used to terminate the literal, injecting arbitrary Javascript code into the Go template. As ES6 template literals are rather complex, and themselves can do string interpolation, the decision was made to simply

CWE-94Oct 12, 2023
CVSS9.8v3.1EPSS0.75%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX