Bugzilla – Bug 1218204
VUL-0: CVE-2023-32728: zabbix: insufficient input validation in Zabbix Agent 2 on item key smart.disk.get can results in remote code execution.
Last modified: 2023-12-24 09:16:51 UTC
The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability for remote code execution. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-32728 https://support.zabbix.com/browse/ZBX-23858 Patch: https://github.com/zabbix/zabbix/commit/73121b6e646078415809296e4525214001b9b9ce https://github.com/zabbix/zabbix/commit/6bda08bf39e870bd258f1684ec0349148a7c6605 https://github.com/zabbix/zabbix/commit/ff07381c4c69c26a5531474750b4e52ee132ade8 https://github.com/zabbix/zabbix/commit/3ce030db643616c81c98886d4c5c131e53a170dd https://github.com/zabbix/zabbix/commit/d79c4fc99ef9c3edf8f05a4f9b07c1a0b2dad64e
not yet relevant to us, it is golang based agent we still not use.