Daniel Leidert pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
1427c246 by Daniel Leidert at 2026-08-09T14:40:37+02:00
Add patch links for open Zabbix issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -73772,16 +73772,20 @@ CVE-2026-23928 (The Item history widget (in Zabbix 
7.0+) or the Plain text widge
        [trixie] - zabbix <ignored> (The WEB UI is only supported for access by 
trusted users, no security updates issued for it, #1124558)
        [bookworm] - zabbix <ignored> (The WEB UI is only supported for access 
by trusted users, no security updates issued for it, #1124558)
        NOTE: https://support.zabbix.com/browse/ZBX-27760
+       NOTE: Fixed by: 
https://github.com/zabbix/zabbix/commit/1522d3a2116ad1e10a05ac08bb5f7cd080d1204d
 (master)
+       NOTE: Fixed by: 
https://github.com/zabbix/zabbix/commit/59f436f726cde91c5c5974f7da0cab41e0b8659a
 (7.0.24rc1)
 CVE-2026-23927 (A user able to connect to Agent 2 can inject an Oracle TNS 
connection  ...)
        - zabbix <unfixed> (bug #1137209)
        [trixie] - zabbix <no-dsa> (Minor issue)
        [bookworm] - zabbix <no-dsa> (Minor issue)
        NOTE: https://support.zabbix.com/browse/ZBX-27759
+       NOTE: Fixed by: 
https://github.com/zabbix/zabbix/commit/6c56fc7f360c79688c67cd599787d6b4db2b172d
 (master)
 CVE-2026-23926 (An authenticated (non-super) administrator can create a 
maintenance pe ...)
        - zabbix <unfixed> (bug #1137209)
        [trixie] - zabbix <ignored> (The WEB UI is only supported for access by 
trusted users, no security updates issued for it, #1124558)
        [bookworm] - zabbix <ignored> (The WEB UI is only supported for access 
by trusted users, no security updates issued for it, #1124558)
        NOTE: https://support.zabbix.com/browse/ZBX-27758
+       NOTE: Fixed by: 
https://github.com/zabbix/zabbix/commit/23e7dfef4da5b328b43b941cc77b5264b9e8bf54
 (master)
 CVE-2026-23870 (A denial of service vulnerability could be triggered by 
sending specia ...)
        NOT-FOR-US: React Server
 CVE-2026-21661 (Uncontrolled Search Path Element vulnerability in 
JohnsonControls AC20 ...)
@@ -99267,6 +99271,7 @@ CVE-2026-23924 (Zabbix Agent 2 Docker plugin does not 
properly sanitize the 'doc
        [trixie] - zabbix <no-dsa> (Minor issue)
        [bookworm] - zabbix <no-dsa> (Minor issue)
        NOTE: https://support.zabbix.com/browse/ZBX-27642
+       NOTE: Fixed by: 
https://github.com/zabbix/zabbix/commit/fd652da1fc528d05c7c18dd1e009c20397237f77
 (master)
 CVE-2026-23923 (An unauthenticated attacker can exploit the Frontend 
'validate' action ...)
        - zabbix <not-affected> (Only affects Zabbix 7.4 series)
        NOTE: https://support.zabbix.com/browse/ZBX-27641
@@ -107869,6 +107874,7 @@ CVE-2026-23925 (An authenticated Zabbix user (User 
role) with template/host writ
        [bookworm] - zabbix <ignored> (The WEB UI is only supported for access 
by trusted users, no security updates issued for it, #1124558)
        [bullseye] - zabbix <postponed> (Minor issue, requires authentication 
and write permission)
        NOTE: https://support.zabbix.com/browse/ZBX-27567
+       NOTE: Fixed by: 
https://github.com/zabbix/zabbix/commit/cf7c038497bfa503c8ff391e99018c7d16700422
 (master)
 CVE-2026-20882 (The WebSocket Application Programming Interface lacks 
restrictions on  ...)
        NOT-FOR-US: Mobiliti e-mobi.hu
 CVE-2026-20748 (The WebSocket backend uses charging station identifiers to 
uniquely as ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1427c246758560d83e58b1127df9d18e755ab830

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1427c246758560d83e58b1127df9d18e755ab830
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to