CVE-2024-22119: Stored XSS in graph items select form
Published Feb 9, 2024
·Updated
The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section.
Affected Software
10 affected components
Zabbix Zabbix>=5.0.0<5.0.40
Zabbix Zabbix>=6.0.0<6.0.24
Zabbix Zabbix>=6.4.0<6.4.9
Zabbix Zabbix=7.0.0-alpha1
Zabbix Zabbix=7.0.0-alpha2
Zabbix Zabbix=7.0.0-alpha3
Zabbix Zabbix=7.0.0-alpha4
Zabbix Zabbix=7.0.0-alpha5
Zabbix Zabbix=7.0.0-alpha6
Zabbix Zabbix=7.0.0-alpha7
Remediation
Patch Available
Event History
Feb 9, 2024
CVE Published
via MITRE·08:26 AM
Data Sourced
via MITRE·08:26 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-22119?
The severity of CVE-2024-22119 is not explicitly rated but is linked to improper validation which can lead to security risks.
2
How do I fix CVE-2024-22119?
To fix CVE-2024-22119, ensure that proper input validation is implemented for the 'Name' form field on the Graph page.
3
What versions of Zabbix are affected by CVE-2024-22119?
CVE-2024-22119 affects Zabbix versions from 5.0.0 to 5.0.40, from 6.0.0 to 6.0.24, from 6.4.0 to 6.4.9, and various alpha versions of 7.0.0.
4
Is there a workaround for CVE-2024-22119?
There are no documented workarounds for CVE-2024-22119, so applying the fix is the recommended action.
5
Who reported CVE-2024-22119?
CVE-2024-22119 was reported in the context of an analysis by Zabbix, with further details outlined in their issue tracking system.