PT-2024-9095 · Zabbix+4 · Zabbix+4
Vjaceslavs Bogdanovs
·
Published
2024-05-28
·
Updated
2025-03-26
·
CVE-2024-36467
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Zabbix (affected versions not specified)
Description:
The issue is related to weaknesses in the authorization procedure of the Zabbix monitoring system. It allows a remote attacker to elevate their privileges. An authenticated user with access to the API, specifically the
user.update API endpoint, can add themselves to any group, except for disabled groups or those with restricted GUI access.Recommendations:
For all affected versions, consider restricting access to the
user.update API endpoint until a patch is available.
As a temporary workaround, restrict users' ability to add themselves to sensitive groups, such as Administrators.
Limit API access to only necessary users and roles to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Red Os
Zabbix