Impact
The JavaScript preprocessing engine (Duktape) on Zabbix server allows a privileged but limited administrator to read raw heap data from other running preprocessors. This memory safety flaw (CWE-125) can lead to disclosure of sensitive information that should not be accessible to that administrator.
Affected Systems
The affected product is the Zabbix server component that uses the Duktape JavaScript engine for preprocessing. Vendors impacted are Zabbix. No specific version range is listed, so any installation using this component is susceptible until upgraded to a fixed release.
Risk and Exploitability
The CVSS score is 6.9, indicating a medium level of severity. The EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog, suggesting it has not yet been widely exploited. Exploitation appears to require administrator privileges on the Zabbix server; a limited administrator could trigger the memory disclosure, so the attack vector is local privilege over the Zabbix server.
OpenCVE Enrichment