[Git][security-tracker-team/security-tracker][master] Add patch links for open Zabbix issues

Daniel Leidert (@dleidert) dleidert at debian.org
Sun Aug 9 13:41:22 BST 2026



Daniel Leidert pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1427c246 by Daniel Leidert at 2026-08-09T14:40:37+02:00
Add patch links for open Zabbix issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -73772,16 +73772,20 @@ CVE-2026-23928 (The Item history widget (in Zabbix 7.0+) or the Plain text widge
 	[trixie] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
 	[bookworm] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
 	NOTE: https://support.zabbix.com/browse/ZBX-27760
+	NOTE: Fixed by: https://github.com/zabbix/zabbix/commit/1522d3a2116ad1e10a05ac08bb5f7cd080d1204d (master)
+	NOTE: Fixed by: https://github.com/zabbix/zabbix/commit/59f436f726cde91c5c5974f7da0cab41e0b8659a (7.0.24rc1)
 CVE-2026-23927 (A user able to connect to Agent 2 can inject an Oracle TNS connection  ...)
 	- zabbix <unfixed> (bug #1137209)
 	[trixie] - zabbix <no-dsa> (Minor issue)
 	[bookworm] - zabbix <no-dsa> (Minor issue)
 	NOTE: https://support.zabbix.com/browse/ZBX-27759
+	NOTE: Fixed by: https://github.com/zabbix/zabbix/commit/6c56fc7f360c79688c67cd599787d6b4db2b172d (master)
 CVE-2026-23926 (An authenticated (non-super) administrator can create a maintenance pe ...)
 	- zabbix <unfixed> (bug #1137209)
 	[trixie] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
 	[bookworm] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
 	NOTE: https://support.zabbix.com/browse/ZBX-27758
+	NOTE: Fixed by: https://github.com/zabbix/zabbix/commit/23e7dfef4da5b328b43b941cc77b5264b9e8bf54 (master)
 CVE-2026-23870 (A denial of service vulnerability could be triggered by sending specia ...)
 	NOT-FOR-US: React Server
 CVE-2026-21661 (Uncontrolled Search Path Element vulnerability in JohnsonControls AC20 ...)
@@ -99267,6 +99271,7 @@ CVE-2026-23924 (Zabbix Agent 2 Docker plugin does not properly sanitize the 'doc
 	[trixie] - zabbix <no-dsa> (Minor issue)
 	[bookworm] - zabbix <no-dsa> (Minor issue)
 	NOTE: https://support.zabbix.com/browse/ZBX-27642
+	NOTE: Fixed by: https://github.com/zabbix/zabbix/commit/fd652da1fc528d05c7c18dd1e009c20397237f77 (master)
 CVE-2026-23923 (An unauthenticated attacker can exploit the Frontend 'validate' action ...)
 	- zabbix <not-affected> (Only affects Zabbix 7.4 series)
 	NOTE: https://support.zabbix.com/browse/ZBX-27641
@@ -107869,6 +107874,7 @@ CVE-2026-23925 (An authenticated Zabbix user (User role) with template/host writ
 	[bookworm] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
 	[bullseye] - zabbix <postponed> (Minor issue, requires authentication and write permission)
 	NOTE: https://support.zabbix.com/browse/ZBX-27567
+	NOTE: Fixed by: https://github.com/zabbix/zabbix/commit/cf7c038497bfa503c8ff391e99018c7d16700422 (master)
 CVE-2026-20882 (The WebSocket Application Programming Interface lacks restrictions on  ...)
 	NOT-FOR-US: Mobiliti e-mobi.hu
 CVE-2026-20748 (The WebSocket backend uses charging station identifiers to uniquely as ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1427c246758560d83e58b1127df9d18e755ab830

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1427c246758560d83e58b1127df9d18e755ab830
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260809/ab3b5f8d/attachment.htm>


More information about the debian-security-tracker-commits mailing list