Zabbix Agent 2 Docker plugin does not properly sanitize...
Moderate severity
Unreviewed
Published
Mar 24, 2026
to the GitHub Advisory Database
•
Updated Mar 24, 2026
Description
Published by the National Vulnerability Database
Mar 24, 2026
Published to the GitHub Advisory Database
Mar 24, 2026
Last updated
Mar 24, 2026
Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker containers by injecting them via the Docker archive API.
References