CVE-2023-32724: JavaScript engine memory pointers are directly available for Zabbix users for modification
Published Oct 12, 2023
·Updated
Memory pointer is in a property of the Ducktape object. This leads to multiple vulnerabilities related to direct memory access and manipulation.
Affected Software
6 affected components
Zabbix Zabbix>=5.0.0<=5.0.36
Zabbix Zabbix>=6.0.0<=6.0.20
Zabbix Zabbix>=6.4.0<=6.4.5
Zabbix Zabbix=7.0.0-alpha1
Zabbix Zabbix=7.0.0-alpha2
Zabbix Zabbix=7.0.0-alpha3
Event History
Oct 12, 2023
CVE Published
via MITRE·06:14 AM
Data Sourced
via MITRE·06:14 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-32724.
2
How severe is this vulnerability?
This vulnerability has a severity rating of 8.8 (critical).
3
What is the affected software?
The affected software is Zabbix Zabbix versions 5.0.0 to 5.0.36, 6.0.0 to 6.0.20, and 6.4.0 to 6.4.5.
4
What are the potential consequences of this vulnerability?
This vulnerability can lead to multiple vulnerabilities related to direct memory access and manipulation.
5
Is there a fix available for this vulnerability?
Yes, a fix is available. Please refer to the Zabbix support page for more details: [https://support.zabbix.com/browse/ZBX-23391](https://support.zabbix.com/browse/ZBX-23391).