CVE-2023-29449: Limited control of resource utilization in JS preprocessing
JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles (Admin and Superadmin). Administrative privileges should be typically granted to users who need to perform tasks that require more control over the system. The security risk is limited because not all users have this level of access.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-29449?
CVE-2023-29449 is a vulnerability that allows JavaScript preprocessing, webhooks, and global scripts to cause uncontrolled CPU, memory, and disk I/O utilization in Zabbix versions 5.0.31 up to and including 6.4.4.
How severe is CVE-2023-29449?
CVE-2023-29449 has a severity score of 4.9, which is considered medium.
Can non-administrative roles exploit CVE-2023-29449?
No, the configuration and testing of preprocessing, webhooks, and global scripts are only available to Administrative roles (Admin and Superadmin).
How can I fix CVE-2023-29449?
To fix CVE-2023-29449, it is recommended to upgrade to a Zabbix version higher than 6.4.4 or apply the necessary patches provided by Zabbix. Additionally, make sure to grant administrative privileges responsibly.
Where can I find more information about CVE-2023-29449?
You can find more information about CVE-2023-29449 at the following reference link: [Support Ticket ZBX-22589](https://support.zabbix.com/browse/ZBX-22589).