CVE-2023-29449
Last modified
CVE-2023-29449 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles (Admin and Superadmin). EPSS estimates a 0.99% chance of exploitation in the next 30 days.
Description
JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles (Admin and Superadmin). Administrative privileges should be typically granted to users who need to perform tasks that require more control over the system. The security risk is limited because not all users have this level of access.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Zabbix | Zabbix | <= 5.0.31 | — |
| Zabbix | Zabbix | >= 6.0.0, <= 6.0.13 | — |
| Zabbix | Zabbix | >= 6.4.1, <= 6.4.4 | — |
| Zabbix | Zabbix | 6.4.0 | Alpha1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-29449?
How severe is CVE-2023-29449?
How do I fix CVE-2023-29449?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-29442Zoho ManageEngine Applications Manager before 16400 allows p…6.1
- CVE-2023-29443Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk…4.9
- CVE-2023-29444An uncontrolled search path element vulnerability (DLL hijac…7.3
- CVE-2023-29445An uncontrolled search path element vulnerability (DLL hijac…7.8
- CVE-2023-29446An improper input validation vulnerability has been discover…4.7
- CVE-2023-29447An insufficiently protected credentials vulnerability in KEP…5.3
- CVE-2023-2945Missing Authorization in GitHub repository openemr/openemr p…5.4
- CVE-2023-29450JavaScript pre-processing can be used by the attacker to gai…7.5
- CVE-2023-29451Specially crafted string can cause a buffer overrun in the J…7.5
- CVE-2023-29452 Currently, geomap configuration (Administration -> General …5.4
- CVE-2023-29453Templates do not properly consider backticks (`) as Javascri…9.8
- CVE-2023-29454Stored or persistent cross-site scripting (XSS) is a type of…5.4
Are you affected by CVE-2023-29449?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
