Bugzilla – Bug 1218185
VUL-0: CVE-2023-32725: zabbix: insufficient validation checks with cookies
Last modified: 2023-12-24 09:31:39 UTC
The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-32725 https://support.zabbix.com/browse/ZBX-23854 Patch: https://github.com/zabbix/zabbix/commit/648cad7e91f1917b2b6a10f43f3c437be041153c
patching in progress