Zabbix Agent 2
cpe:2.3:a:zabbix:zabbix-agent2:*:*:*:*:*:*:*
- >= 6.0.0, <= 6.0.43
- >= 7.0.0, <= 7.0.22
- >= 7.4.0, <= 7.4.6
A vulnerability exists in the Zabbix Agent 2 Docker plugin, specifically in versions 6.0.0 prior to 6.0.44, 7.0.0 prior to 7.0.23, and 7.4.0 prior to 7.4.7. The issue arises because the plugin fails to properly sanitize the 'docker.container_info' parameters before forwarding them to the Docker daemon. This lack of validation allows an attacker who can invoke Agent 2 to read arbitrary files from running Docker containers by injecting requests through the Docker archive API.
Exploitation of this vulnerability allows for arbitrary file read from Docker containers, potentially leading to exposure of sensitive information or files on the host system.
Users can update to Zabbix Agent 2 versions 6.0.44, 7.0.23, or 7.4.7 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.