CVE-2023-29456: Inefficient URL schema validation
Published Jul 13, 2023
·Updated
URL validation scheme receives input from a user and then parses it to identify its various components. The validation scheme can ensure that all URL components comply with internet standards.
Affected Software
4 affected components
Zabbix Frontend>=4.0.0<=4.0.46
Zabbix Frontend>=5.0.0<=5.0.35
Zabbix Frontend>=6.0.0<=6.0.18
Zabbix Frontend>=6.4.0<=6.4.3
Remediation
Patch Available
Event History
Jul 13, 2023
CVE Published
via MITRE·09:33 AM
Data Sourced
via MITRE·09:33 AM
DescriptionSeverityWeakness
Data Sourced
10:15 AM
Description
Data Sourced
via NVD·10:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-29456?
CVE-2023-29456 is a vulnerability in the URL validation scheme used by Zabbix Frontend software.
2
What is the severity of CVE-2023-29456?
The severity of CVE-2023-29456 is medium with a CVSS score of 5.4.
3
How does CVE-2023-29456 affect Zabbix Frontend software?
CVE-2023-29456 affects Zabbix Frontend software versions 4.0.0 to 4.0.46, 5.0.0 to 5.0.35, 6.0.0 to 6.0.18, and 6.4.0 to 6.4.3.
4
What is the CWE of CVE-2023-29456?
The CWE (Common Weakness Enumeration) of CVE-2023-29456 is CWE-79 and CWE-20.
5
How can I fix CVE-2023-29456?
To fix CVE-2023-29456, update your Zabbix Frontend software to a version that is not affected by the vulnerability.