CVE-2024-42325
Last modified
CVE-2024-42325 is a low-severity vulnerability rated 2.1/10 on the CVSS scale. Zabbix API user.get returns all users that share common group with the calling user. This includes media and other information, such as login attempts, etc.. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
Zabbix API user.get returns all users that share common group with the calling user. This includes media and other information, such as login attempts, etc.
Metrics
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zabbix | Zabbix | >= 5.0.0, < 5.0.46 |
| Zabbix | Zabbix | >= 6.0.0, < 6.0.38 |
| Zabbix | Zabbix | >= 7.0.0, < 7.0.9 |
| Zabbix | Zabbix | >= 7.2.0, < 7.2.3 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-42325?
How severe is CVE-2024-42325?
How do I fix CVE-2024-42325?
Are you affected by CVE-2024-42325?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
