Bug 1213301 (CVE-2023-29449) - VUL-0: CVE-2023-29449: zabbix: JavaScript can cause uncontrolled CPU, memory, and disk I/O utilization
Summary: VUL-0: CVE-2023-29449: zabbix: JavaScript can cause uncontrolled CPU, memory,...
Status: RESOLVED FIXED
Alias: CVE-2023-29449
Product: openSUSE Distribution
Classification: openSUSE
Component: Network (show other bugs)
Version: Leap 15.5
Hardware: Other Other
: P3 - Medium : Normal (vote)
Target Milestone: Leap 15.5
Assignee: Boris Manojlovic
QA Contact: E-mail List
URL: https://smash.suse.de/issue/372378/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-29449:5.9:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2023-07-13 20:51 UTC by Stoyan Manolov
Modified: 2023-07-20 20:41 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stoyan Manolov 2023-07-13 20:51:04 UTC
CVE-2023-29449

JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles (Admin and Superadmin). Administrative privileges should be typically granted to users who need to perform tasks that require more control over the system. The security risk is limited because not all users have this level of access.

Reference:
https://support.zabbix.com/browse/ZBX-22589

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-29449
https://bugzilla.redhat.com/show_bug.cgi?id=2222680
https://www.cve.org/CVERecord?id=CVE-2023-29449
https://support.zabbix.com/browse/ZBX-22589
Comment 1 Petr Gajdos 2023-07-19 10:24:00 UTC
Adding Boris, the openSUSE maintainer.
Comment 3 Petr Gajdos 2023-07-20 09:31:35 UTC
As far as I can see, zbxembed is not available in 4.0. With that I would consider 12sp3/zabbix unaffected.
Comment 6 Petr Gajdos 2023-07-20 11:30:30 UTC
Reassigning to Boris.

@Boris, if I am supposed to help somehow, fx. to send an Backports version update, let me know. Likewise, if you spot an error in my reasoning.
Comment 7 Boris Manojlovic 2023-07-20 20:41:22 UTC
(In reply to Petr Gajdos from comment #6)
> Reassigning to Boris.
> 
> @Boris, if I am supposed to help somehow, fx. to send an Backports version
> update, let me know. Likewise, if you spot an error in my reasoning.

that is correct, as can be seen in linked support ticket on zabbix site.
Fix Version/s 		6.4.0rc1 [ 21104 ]
Fix Version/s 		6.2.8rc1 [ 21103 ]
Fix Version/s 		6.0.14rc1 [ 21102 ]
Fix Version/s 		5.0.32rc1 [ 21100 ]

and we are on 6.0.17 version in Factory, and by the way if someone is admin on zabbix server (web interface) he almost by design has access to functionality that allows access to server (if agent is installed)