Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-46768


Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper validation for URL parameters before reading the files.


Published

2022-12-15T07:15:09.733

Last Modified

2024-11-21T07:31:01.430

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-20
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application zabbix web_service_report_generation ≤ 6.0.11 Yes
Application zabbix web_service_report_generation ≤ 6.2.5 Yes
Application zabbix zabbix-agent2 < 6.0.12 Yes
Application zabbix zabbix-agent2 < 6.2.6 Yes

References