First published: Thu Jul 13 2023(Updated: )
URL validation scheme receives input from a user and then parses it to identify its various components. The validation scheme can ensure that all URL components comply with internet standards.
Credit: security@zabbix.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zabbix | >=4.0.0<=4.0.46 | |
Zabbix | >=5.0.0<=5.0.35 | |
Zabbix | >=6.0.0<=6.0.18 | |
Zabbix | >=6.4.0<=6.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-29456 is a vulnerability in the URL validation scheme used by Zabbix Frontend software.
The severity of CVE-2023-29456 is medium with a CVSS score of 5.4.
CVE-2023-29456 affects Zabbix Frontend software versions 4.0.0 to 4.0.46, 5.0.0 to 5.0.35, 6.0.0 to 6.0.18, and 6.4.0 to 6.4.3.
The CWE (Common Weakness Enumeration) of CVE-2023-29456 is CWE-79 and CWE-20.
To fix CVE-2023-29456, update your Zabbix Frontend software to a version that is not affected by the vulnerability.