Vulnerability CVE-2023-32725: Information

Description

The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.

Severity: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Published: Dec. 18, 2023
Modified: Dec. 22, 2023
Error type identifier: CWE-565

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
zabbixsisyphus6.0.27-alt16.0.30-alt1ALT-PU-2024-3075-1341482Fixed
zabbixsisyphus_e2k6.0.27-alt26.0.29-alt1ALT-PU-2024-4292-1-Fixed
zabbixsisyphus_riscv646.0.27-alt16.0.30-alt1ALT-PU-2024-4119-1-Fixed
zabbixsisyphus_loongarch646.0.27-alt16.0.30-alt1ALT-PU-2024-3139-1-Fixed
zabbixp106.0.27-alt0.p10.16.0.29-alt0.p10.1ALT-PU-2024-3077-2341483Fixed
zabbixp10_e2k6.0.27-alt0.p10.16.0.29-alt0.p10.1ALT-PU-2024-4325-1-Fixed
zabbixc10f16.0.27-alt0.c10f1.16.0.27-alt0.c10f1.1ALT-PU-2024-3365-2341486Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://support.zabbix.com/browse/ZBX-23854
  • Vendor Advisory
    1. Configuration 1

      cpe:2.3:a:zabbix:zabbix_server:7.0.0:alpha1:*:*:*:*:*:*

      cpe:2.3:a:zabbix:zabbix_server:7.0.0:alpha2:*:*:*:*:*:*

      cpe:2.3:a:zabbix:zabbix_server:7.0.0:alpha3:*:*:*:*:*:*

      cpe:2.3:a:zabbix:zabbix_server:*:*:*:*:*:*:*:*
      Start including
      6.4.0
      End including
      6.4.6

      cpe:2.3:a:zabbix:zabbix_server:*:*:*:*:*:*:*:*
      Start including
      6.0.0
      End including
      6.0.21

      Configuration 2

      cpe:2.3:a:zabbix:frontend:7.0.0:alpha3:*:*:*:*:*:*

      cpe:2.3:a:zabbix:frontend:7.0.0:alpha2:*:*:*:*:*:*

      cpe:2.3:a:zabbix:frontend:7.0.0:alpha1:*:*:*:*:*:*

      cpe:2.3:a:zabbix:frontend:*:*:*:*:*:*:*:*
      Start including
      6.4.0
      End including
      6.4.6

      cpe:2.3:a:zabbix:frontend:*:*:*:*:*:*:*:*
      Start including
      6.0.0
      End including
      6.0.21