Impact
A use‑after‑free flaw in Zabbix’s script item/preprocessing logic allows a Zabbix administrator to trigger a read of memory beyond the bounds of an HTTP request buffer. The vulnerability is triggered when a preprocessor script includes a JavaScript HttpRequest, and an attacker can cause the server to emit a memory access that leaks sensitive data, leading to potential confidentiality loss.
Affected Systems
Zabbix – the description does not specify affected component versions. Any installation that relies on the vulnerable script item/preprocessing API is potentially impacted.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate severity, and the vulnerability is not listed in the KEV catalog. The EPSS score is not available, so the current likelihood of exploitation is unknown, but the flaw requires administrative privileges or the ability to add or alter preprocessor scripts. If these conditions are satisfied, an attacker can read arbitrary data from the Zabbix process, compromising confidentiality. The exploit path is local to the Zabbix database server and does not provide elevated privilege escalation beyond the preprocessor context.
OpenCVE Enrichment