Zabbix Vulnerabilities and Affected Products
Vulnerabilities associated with zabbix-agent2.
Products
Clear product- Zabbix68 vulnerabilities
- Frontend12 vulnerabilities
- Zabbix agent 2 (MSI packages)2 vulnerabilities
- Proxy, Server1 vulnerability
- Web Service Report Generation1 vulnerability
- Zabbix agent (MSI packages)1 vulnerability
- Zabbix Server1 vulnerability
- zabbix-agent21 vulnerability
- zabbix_server1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-29453CRITICAL | Agent 2 package are built with Go version affected by CVE-2023-24538Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the action can be used to terminate the literal, injecting arbitrary Javascript code into the Go template. As ES6 template literals are rather complex, and themselves can do string interpolation, the decision was made to simply… CWE-94Oct 12, 2023 | CVSS9.8v3.1 | EPSS0.75% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |