Files
packages/admin
Daniel F. Dickinson 0488c96b08 zabbix: update to 7.0.21 (lts)
Updates Zabbix to 7.0.21-r1 (latest 7.0 LTS version)

Note that for the frontend, clearing browser cache, cookies and other
site data for the zabbix frontend server may be necessary.

Security fixes compared to 7.0.12 (most are frontend only):

* CVE-2025-27238: API hostprototype.get lists data to users with
  insufficient authorization https://support.zabbix.com/browse/ZBX-26988
* CVE-2025-27236: User information disclosure via api_jsonrpc.php on
  method user.get with param search:
  https://support.zabbix.com/browse/ZBX-27060
* CVE-2025-27231: LDAP 'Bind password' field value can be leaked by a
  Zabbix Super Admin: https://support.zabbix.com/browse/ZBX-27062
* CVE-2025-49641: Insufficient permission check for the
  problem.view.refresh action:
  https://support.zabbix.com/browse/ZBX-27063
* CVE-2025-49643: Frontend DoS vulnerability due to asymmetric
  resource consumption: https://support.zabbix.com/browse/ZBX-27284

Signed-off-by: Daniel F. Dickinson <dfdpublic@wildtechgarden.ca>
2025-12-20 11:19:45 +01:00
..
2025-07-27 22:26:58 +02:00
2025-08-23 13:28:18 +03:00
2025-09-22 17:17:09 +08:00
2025-11-03 02:29:41 +02:00
2025-11-23 08:45:50 +01:00
2025-05-02 10:28:24 +02:00
2025-08-14 12:00:01 +08:00
2025-04-15 02:56:17 +08:00
2025-06-08 22:52:00 +03:00
2024-06-23 11:05:02 -07:00
2023-04-21 22:46:58 +02:00
2023-04-21 22:46:58 +02:00
2023-07-07 13:29:50 +02:00
2025-08-11 17:10:46 +08:00
2025-08-12 20:56:54 +02:00
2025-12-20 11:19:45 +01:00