CVE-2024-42327
9.9
CRITICAL
CVSS 3.1
EPSS 78.8%
描述
A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is being called from the CUser.get function which is available for every user who has API access.
如何修補 CVE-2024-42327
目前尚未發布修補版本。可考慮移除受影響套件,或參考下方連結中的上游建議。
- Debian/zabbix—未列出修補版本
CVE-2024-42327 正在被利用嗎?
可能 — EPSS 為 78.8%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- from 0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.9 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |