rpm package
opensuse/zabbix&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/zabbix&distro=openSUSE%20Tumbleweed
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-42502 | Med | 6.1 | < 7.0.28-1.1 | 7.0.28-1.1 | May 22, 2026 | Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering. | |
| CVE-2026-25680 | Med | 6.5 | < 7.0.28-1.1 | 7.0.28-1.1 | May 22, 2026 | Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service. | |
| CVE-2024-36461 | Cri | 9.1 | < 6.0.33-1.1 | 6.0.33-1.1 | Aug 12, 2024 | Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine. | |
| CVE-2023-32727 | Med | 6.8 | < 6.0.25-1.1 | 6.0.25-1.1 | Dec 18, 2023 | An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server. |
- affected < 7.0.28-1.1fixed 7.0.28-1.1
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
- affected < 7.0.28-1.1fixed 7.0.28-1.1
Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.
- affected < 6.0.33-1.1fixed 6.0.33-1.1
Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.
- affected < 6.0.25-1.1fixed 6.0.25-1.1
An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.