An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to other authenticated users in order to create a fake account with predefined login, password and role in Zabbix Frontend.
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "1:6.0.29+dfsg-1",
"binary_name": "zabbix-agent"
},
{
"binary_version": "1:6.0.29+dfsg-1",
"binary_name": "zabbix-agent-dbgsym"
},
{
"binary_version": "1:6.0.29+dfsg-1",
"binary_name": "zabbix-agent2"
},
{
"binary_version": "1:6.0.29+dfsg-1",
"binary_name": "zabbix-agent2-dbgsym"
},
{
"binary_version": "1:6.0.29+dfsg-1",
"binary_name": "zabbix-frontend-php"
},
{
"binary_version": "1:6.0.29+dfsg-1",
"binary_name": "zabbix-java-gateway"
},
{
"binary_version": "1:6.0.29+dfsg-1",
"binary_name": "zabbix-proxy-mysql"
},
{
"binary_version": "1:6.0.29+dfsg-1",
"binary_name": "zabbix-proxy-mysql-dbgsym"
},
{
"binary_version": "1:6.0.29+dfsg-1",
"binary_name": "zabbix-proxy-pgsql"
},
{
"binary_version": "1:6.0.29+dfsg-1",
"binary_name": "zabbix-proxy-pgsql-dbgsym"
},
{
"binary_version": "1:6.0.29+dfsg-1",
"binary_name": "zabbix-proxy-sqlite3"
},
{
"binary_version": "1:6.0.29+dfsg-1",
"binary_name": "zabbix-proxy-sqlite3-dbgsym"
},
{
"binary_version": "1:6.0.29+dfsg-1",
"binary_name": "zabbix-server-mysql"
},
{
"binary_version": "1:6.0.29+dfsg-1",
"binary_name": "zabbix-server-mysql-dbgsym"
},
{
"binary_version": "1:6.0.29+dfsg-1",
"binary_name": "zabbix-server-pgsql"
},
{
"binary_version": "1:6.0.29+dfsg-1",
"binary_name": "zabbix-server-pgsql-dbgsym"
},
{
"binary_version": "1:6.0.29+dfsg-1",
"binary_name": "zabbix-web-service"
},
{
"binary_version": "1:6.0.29+dfsg-1",
"binary_name": "zabbix-web-service-dbgsym"
}
],
"ubuntu_priority": "medium"
}