Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper validation for URL parameters before reading the files.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-49551 Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper validation for URL parameters before reading the files.
Fixes

Solution

To remediate this vulnerability, apply updates to the appropriate products or use the workaround


Workaround

If an immediate update is not possible, limit network access to Zabbix Web Service Report Generation.

History

Wed, 16 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zabbix

Published:

Updated: 2025-04-16T13:50:46.579Z

Reserved: 2022-12-07T00:00:00.000Z

Link: CVE-2022-46768

cve-icon Vulnrichment

Updated: 2024-08-03T14:39:38.708Z

cve-icon NVD

Status : Modified

Published: 2022-12-15T07:15:09.733

Modified: 2024-11-21T07:31:01.430

Link: CVE-2022-46768

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.