CVE-2023-32723: Inefficient permission check in class CControllerAuthenticationUpdate
Published Oct 12, 2023
·Updated
Request to LDAP is sent before user permissions are checked.
Affected Software
5 affected components
Zabbix Zabbix>=4.0.0<4.0.19
Zabbix Zabbix>=4.4.0<4.4.7
Zabbix Zabbix=4.0.19-rc1
Zabbix Zabbix=4.4.7-rc1
Zabbix Zabbix=5.0.0-alpha3
Event History
Oct 12, 2023
CVE Published
via MITRE·06:11 AM
Data Sourced
via MITRE·06:11 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-32723.
2
What is the severity of CVE-2023-32723?
The severity of CVE-2023-32723 is critical.
3
What is the affected software for CVE-2023-32723?
The affected software for CVE-2023-32723 is Zabbix versions 4.0.0 to 4.0.19, 4.4.0 to 4.4.7, 4.0.19-rc1, 4.4.7-rc1, and 5.0.0-alpha3.
4
What is the description of CVE-2023-32723?
CVE-2023-32723 is a vulnerability where a request to LDAP is sent before user permissions are checked in Zabbix.
5
Is there a fix available for CVE-2023-32723?
Yes, a fix is available for CVE-2023-32723. Please refer to the reference link for more information.