First published: Thu Oct 12 2023(Updated: )
Request to LDAP is sent before user permissions are checked.
Credit: security@zabbix.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zabbix Server | >=4.0.0<4.0.19 | |
Zabbix Server | >=4.4.0<4.4.7 | |
Zabbix Server | =4.0.19-rc1 | |
Zabbix Server | =4.4.7-rc1 | |
Zabbix Server | =5.0.0-alpha3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-32723.
The severity of CVE-2023-32723 is critical.
The affected software for CVE-2023-32723 is Zabbix versions 4.0.0 to 4.0.19, 4.4.0 to 4.4.7, 4.0.19-rc1, 4.4.7-rc1, and 5.0.0-alpha3.
CVE-2023-32723 is a vulnerability where a request to LDAP is sent before user permissions are checked in Zabbix.
Yes, a fix is available for CVE-2023-32723. Please refer to the reference link for more information.