« Volver al listado

CVE-2023-32725

Estado: ModificadaAlta (8.8)—

The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-32725",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@zabbix.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9.6,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@zabbix.com",
      "affectedData": [
        {
          "repo": "https://git.zabbix.com/",
          "vendor": "Zabbix",
          "modules": [
            "Server",
            "Web service"
          ],
          "product": "Zabbix",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "6.0.22rc1",
                  "status": "unaffected"
                }
              ],
              "version": "6.0.0 ",
              "versionType": "git",
              "lessThanOrEqual": "6.0.21"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "6.4.7rc1",
                  "status": "unaffected"
                }
              ],
              "version": "6.4.0",
              "versionType": "git",
              "lessThanOrEqual": "6.4.6"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "7.0.0alpha4",
                  "status": "unaffected"
                }
              ],
              "version": "7.0.0alpha1 ",
              "versionType": "git",
              "lessThanOrEqual": "7.0.0alpha3"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-12-18T10:15:06.550",
  "references": [
    {
      "url": "https://support.zabbix.com/browse/ZBX-23854",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@zabbix.com"
    },
    {
      "url": "https://support.zabbix.com/browse/ZBX-23854",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@zabbix.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-565"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-565"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user."
    },
    {
      "lang": "es",
      "value": "El sitio web configurado en el widget de la URL recibirá una cookie de sesión al probar o ejecutar informes programados. La cookie de sesión recibida se puede utilizar para acceder a la interfaz como usuario particular."
    }
  ],
  "lastModified": "2026-06-17T05:59:27.780",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:zabbix:zabbix_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F99748EE-AE9C-4210-ABCD-10A5E6E7E58E",
              "versionEndIncluding": "6.0.21",
              "versionStartIncluding": "6.0.0"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:zabbix_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "86A23392-9192-4CCA-BC7C-C4EEFB2C2B97",
              "versionEndIncluding": "6.4.6",
              "versionStartIncluding": "6.4.0"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:zabbix_server:7.0.0:alpha1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0DC55403-7711-4719-A309-2616586ED479"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:zabbix_server:7.0.0:alpha2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1BB0DFCF-6ED3-4BA3-8B3F-D1F6D06A08DB"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:zabbix_server:7.0.0:alpha3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0B17E6DD-0DA4-4002-B2D2-C16EED6C97BA"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:zabbix:frontend:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A064CA46-1D9A-434E-B099-B3477BA2D14D",
              "versionEndIncluding": "6.0.21",
              "versionStartIncluding": "6.0.0"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:frontend:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DD82A00A-587E-4C1F-80CC-474A4A1D4A07",
              "versionEndIncluding": "6.4.6",
              "versionStartIncluding": "6.4.0"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:frontend:7.0.0:alpha1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "40AB0231-C1C8-4D97-96B7-E293DD7250A7"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:frontend:7.0.0:alpha2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9E5DF882-2A9F-4881-A0F7-FFC804B65495"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:frontend:7.0.0:alpha3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "79886648-EEC0-44B3-8788-2F0A65B1FB1A"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@zabbix.com"
}