USN-6751-1: Zabbix vulnerabilities
It was discovered that Zabbix incorrectly handled input data in the discovery and graphs pages. A remote authenticated attacker could possibly use this issue to perform reflected cross-site scripting (XSS) attacks. (CVE-2022-35229, CVE-2022-35230)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6751-1?
The severity of USN-6751-1 is categorized as medium due to its potential for reflected cross-site scripting (XSS) attacks.
How do I fix USN-6751-1?
To fix USN-6751-1, update your Zabbix packages to versions 1:5.0.17+dfsg-1ubuntu0.1~esm1 or later for Ubuntu 22.04.
What packages are affected by USN-6751-1?
The affected packages in USN-6751-1 include zabbix-agent, zabbix-frontend-php, zabbix-java-gateway, zabbix-proxy-mysql, zabbix-proxy-pgsql, zabbix-proxy-sqlite3, zabbix-server-mysql, and zabbix-server-pgsql.
Who is affected by USN-6751-1?
Users of Ubuntu 22.04 running the specified Zabbix packages are affected by USN-6751-1.
What is cross-site scripting in the context of USN-6751-1?
Cross-site scripting (XSS) in USN-6751-1 refers to a vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.