ELA-406-1 zabbix security update

multiple vulnerabilities

2021-04-21
Packagezabbix
Version1:2.2.23+dfsg-0+deb8u2
Related CVEs CVE-2019-15132 CVE-2020-11800 CVE-2020-15803


Multiple vulnerabilities were discovered in Zabbix, a network monitoring solution. An attacker may remotely execute code on the zabbix server, enumerate valid users and redirect to external links through the zabbix web frontend.



For Debian 8 jessie, these problems have been fixed in version 1:2.2.23+dfsg-0+deb8u2.

We recommend that you upgrade your zabbix packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.