Medium severity5.9NVD Advisory· Published Jul 13, 2023· Updated Jun 17, 2026
CVE-2023-29449
CVE-2023-29449
Description
JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles (Admin and Superadmin). Administrative privileges should be typically granted to users who need to perform tasks that require more control over the system. The security risk is limited because not all users have this level of access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*+ 12 more
- cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*range: <=5.0.31
- cpe:2.3:a:zabbix:zabbix:6.4.0:alpha1:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:6.4.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:6.4.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:6.4.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:6.4.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:6.4.0:beta5:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:6.4.0:beta6:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:6.4.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:6.4.0:rc3:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:6.4.0:rc4:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: 4.4.4
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.