An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to other authenticated users in order to create a fake account with predefined login, password and role in Zabbix Frontend.
{
"ubuntu_priority": "medium",
"binaries": [
{
"binary_name": "zabbix-agent",
"binary_version": "1:6.0.29+dfsg-1"
},
{
"binary_name": "zabbix-agent-dbgsym",
"binary_version": "1:6.0.29+dfsg-1"
},
{
"binary_name": "zabbix-agent2",
"binary_version": "1:6.0.29+dfsg-1"
},
{
"binary_name": "zabbix-agent2-dbgsym",
"binary_version": "1:6.0.29+dfsg-1"
},
{
"binary_name": "zabbix-frontend-php",
"binary_version": "1:6.0.29+dfsg-1"
},
{
"binary_name": "zabbix-java-gateway",
"binary_version": "1:6.0.29+dfsg-1"
},
{
"binary_name": "zabbix-proxy-mysql",
"binary_version": "1:6.0.29+dfsg-1"
},
{
"binary_name": "zabbix-proxy-mysql-dbgsym",
"binary_version": "1:6.0.29+dfsg-1"
},
{
"binary_name": "zabbix-proxy-pgsql",
"binary_version": "1:6.0.29+dfsg-1"
},
{
"binary_name": "zabbix-proxy-pgsql-dbgsym",
"binary_version": "1:6.0.29+dfsg-1"
},
{
"binary_name": "zabbix-proxy-sqlite3",
"binary_version": "1:6.0.29+dfsg-1"
},
{
"binary_name": "zabbix-proxy-sqlite3-dbgsym",
"binary_version": "1:6.0.29+dfsg-1"
},
{
"binary_name": "zabbix-server-mysql",
"binary_version": "1:6.0.29+dfsg-1"
},
{
"binary_name": "zabbix-server-mysql-dbgsym",
"binary_version": "1:6.0.29+dfsg-1"
},
{
"binary_name": "zabbix-server-pgsql",
"binary_version": "1:6.0.29+dfsg-1"
},
{
"binary_name": "zabbix-server-pgsql-dbgsym",
"binary_version": "1:6.0.29+dfsg-1"
},
{
"binary_name": "zabbix-web-service",
"binary_version": "1:6.0.29+dfsg-1"
},
{
"binary_name": "zabbix-web-service-dbgsym",
"binary_version": "1:6.0.29+dfsg-1"
}
],
"availability": "No subscription required"
}