PT-2024-8876 · Zabbix+4 · Zabbix+4

Vjaceslavs Bogdanovs

·

Published

2024-11-27

·

Updated

2026-02-01

·

CVE-2024-42327

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Zabbix versions 6.0.0 through 6.0.31 Zabbix versions 6.4.0 through 6.4.16 Zabbix version 7.0.0
Description: A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access, can exploit this vulnerability. An SQL injection exists in the CUser class in the addRelatedObjects function, which is called from the CUser.get function. This function is available for every user who has API access. The vulnerability allows attackers to escalate privileges and gain full control of the system by sending a specially crafted SQL query through the API. Over 143,000 services are potentially affected.
Recommendations: For Zabbix versions 6.0.0 through 6.0.31, update to version 6.0.32rc1 or later. For Zabbix versions 6.4.0 through 6.4.16, update to version 6.4.17rc1 or later. For Zabbix version 7.0.0, update to version 7.0.1rc1 or later. As a temporary workaround, consider restricting access to the CUser.get function and the addRelatedObjects function until a patch is available. Avoid using the API endpoint that calls these functions until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

ALT-PU-2024-16527
ALT-PU-2024-16638
ALT-PU-2025-3400
BDU:2024-10543
CVE-2024-42327

Affected Products

Alt Linux
Astra Linux
Debian
Red Os
Zabbix