Lucene search

K
cvelistZabbixCVELIST:CVE-2023-32724
HistoryOct 12, 2023 - 6:14 a.m.

CVE-2023-32724 JavaScript engine memory pointers are directly available for Zabbix users for modification

2023-10-1206:14:45
CWE-732
Zabbix
www.cve.org
cve-2023-32724
javascript engine
zabbix users
memory pointers
ducktape object
vulnerabilities
memory access

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H

9.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.3%

Memory pointer is in a property of the Ducktape object. This leads to multiple vulnerabilities related to direct memory access and manipulation.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "modules": [
      "Proxy",
      "Server"
    ],
    "product": "Zabbix",
    "repo": "https://git.zabbix.com/",
    "vendor": "Zabbix",
    "versions": [
      {
        "changes": [
          {
            "at": "5.0.37rc1",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "5.0.36",
        "status": "affected",
        "version": "5.0.0",
        "versionType": "git"
      },
      {
        "changes": [
          {
            "at": "6.0.21rc1",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "6.0.20",
        "status": "affected",
        "version": "6.0.0",
        "versionType": "git"
      },
      {
        "changes": [
          {
            "at": "6.4.6rc1",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "6.4.5",
        "status": "affected",
        "version": "6.4.0",
        "versionType": "git"
      },
      {
        "changes": [
          {
            "at": "7.0.0alpha4",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "7.0.0alpha3",
        "status": "affected",
        "version": "7.0.0alpha1",
        "versionType": "git"
      }
    ]
  }
]

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H

9.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.3%

Related for CVELIST:CVE-2023-32724