mirror of
https://github.com/openwrt/packages.git
synced 2025-12-21 17:04:32 +04:00
Updates Zabbix to 7.0.21-r1 (latest 7.0 LTS version) Note that for the frontend, clearing browser cache, cookies and other site data for the zabbix frontend server may be necessary. Security fixes compared to 7.0.12 (most are frontend only): * CVE-2025-27238: API hostprototype.get lists data to users with insufficient authorization https://support.zabbix.com/browse/ZBX-26988 * CVE-2025-27236: User information disclosure via api_jsonrpc.php on method user.get with param search: https://support.zabbix.com/browse/ZBX-27060 * CVE-2025-27231: LDAP 'Bind password' field value can be leaked by a Zabbix Super Admin: https://support.zabbix.com/browse/ZBX-27062 * CVE-2025-49641: Insufficient permission check for the problem.view.refresh action: https://support.zabbix.com/browse/ZBX-27063 * CVE-2025-49643: Frontend DoS vulnerability due to asymmetric resource consumption: https://support.zabbix.com/browse/ZBX-27284 Signed-off-by: Daniel F. Dickinson <dfdpublic@wildtechgarden.ca>