Description
The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 13 | | =1:7.0.10+dfsg-2 || =1:7.0.22+dfsg-1 || =1:7.0.22+dfsg-1.1 || =1:7.0.22+dfsg-1~bpo13+1 || =1:7.0.22+dfsg-1~deb13u1 |
 debian 12 | | =1:6.0.14+dfsg-1 || =1:6.0.23+dfsg-1 || =1:6.0.23+dfsg-1~bpo12+1 || =1:6.0.24+dfsg-1 || =1:6.0.25+dfsg-1 || =1:6.0.29+dfsg-1 || =1:7.0.0+dfsg-1 || =1:7.0.0+dfsg-2 || =1:7.0.0+dfsg-2~bpo12+1 || =1:7.0.1+dfsg-1 || =1:7.0.1+dfsg-1~bpo12+1 || =1:7.0.10+dfsg-1 || =1:7.0.10+dfsg-2 || =1:7.0.2+dfsg-1 || =1:7.0.2+dfsg-1~bpo12+1 || =1:7.0.22+dfsg-1 || =1:7.0.22+dfsg-1.1 || =1:7.0.22+dfsg-1~bpo13+1 || =1:7.0.22+dfsg-1~deb13u1 || =1:7.0.3+dfsg-1 || =1:7.0.5+dfsg-1 || =1:7.0.5+dfsg-1~bpo12+1 || =1:7.0.6+dfsg-1 || =1:7.0.9+dfsg-1 || =1:7.0.9+dfsg-1~bpo12+1 |
 debian 14 | | =1:7.0.10+dfsg-2 || =1:7.0.22+dfsg-1 || =1:7.0.22+dfsg-1.1 || =1:7.0.22+dfsg-1~bpo13+1 || =1:7.0.22+dfsg-1~deb13u1 |
 debian 11 | | =1:5.0.14+dfsg-1 || =1:5.0.14+dfsg-1~bpo11+1 || =1:5.0.17+dfsg-1 || =1:5.0.17+dfsg-1~bpo11+1 || =1:5.0.44+dfsg-1+deb11u1 || =1:5.0.45+dfsg-1+deb11u1 || =1:5.0.46+dfsg-1+deb11u1 || =1:5.0.47+dfsg-0+deb11u1 || =1:5.0.8+dfsg-1 || =1:6.0.10+dfsg-1 || =1:6.0.13+dfsg-1 || =1:6.0.14+dfsg-1 || =1:6.0.14+dfsg-1~bpo11+1 || =1:6.0.23+dfsg-1 || =1:6.0.23+dfsg-1~bpo12+1 || =1:6.0.24+dfsg-1 || =1:6.0.25+dfsg-1 || =1:6.0.29+dfsg-1 || =1:6.0.3+dfsg-1 || =1:6.0.6+dfsg-1 || =1:6.0.7+dfsg-1 || =1:6.0.7+dfsg-2 || =1:6.0.7+dfsg-2~bpo11+1 || =1:6.0.7+dfsg-3 || =1:6.0.8+dfsg-1 || =1:6.0.9+dfsg-1 || =1:6.0.9+dfsg-1.1 || =1:7.0.0+dfsg-1 || =1:7.0.0+dfsg-2 || =1:7.0.0+dfsg-2~bpo12+1 || =1:7.0.1+dfsg-1 || =1:7.0.1+dfsg-1~bpo12+1 || =1:7.0.10+dfsg-1 || =1:7.0.10+dfsg-2 || =1:7.0.2+dfsg-1 || =1:7.0.2+dfsg-1~bpo12+1 || =1:7.0.22+dfsg-1 || =1:7.0.22+dfsg-1.1 || =1:7.0.22+dfsg-1~bpo13+1 || =1:7.0.22+dfsg-1~deb13u1 || =1:7.0.3+dfsg-1 || =1:7.0.5+dfsg-1 || =1:7.0.5+dfsg-1~bpo12+1 || =1:7.0.6+dfsg-1 || =1:7.0.9+dfsg-1 || =1:7.0.9+dfsg-1~bpo12+1 |