PT-2024-9095 · Zabbix+4 · Zabbix+4

Vjaceslavs Bogdanovs

·

Published

2024-05-28

·

Updated

2025-03-26

·

CVE-2024-36467

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Zabbix (affected versions not specified)
Description: The issue is related to weaknesses in the authorization procedure of the Zabbix monitoring system. It allows a remote attacker to elevate their privileges. An authenticated user with access to the API, specifically the user.update API endpoint, can add themselves to any group, except for disabled groups or those with restricted GUI access.
Recommendations: For all affected versions, consider restricting access to the user.update API endpoint until a patch is available. As a temporary workaround, restrict users' ability to add themselves to sensitive groups, such as Administrators. Limit API access to only necessary users and roles to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-16527
ALT-PU-2024-16638
ALT-PU-2025-3400
BDU:2024-10777
CVE-2024-36467
DLA-3909-1

Affected Products

Alt Linux
Astra Linux
Debian
Red Os
Zabbix