CVE-2024-36461: Direct access to memory pointers within the JS engine for modification
Published Aug 9, 2024
·Updated
Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.
Affected Software
3 affected components
Zabbix Zabbix>=6.0.0<=6.0.30
Zabbix Zabbix>=6.4.0<=6.4.15
Zabbix Zabbix=7.0.0
Event History
Aug 9, 2024
CVE Published
via MITRE·09:33 AM
Data Sourced
via MITRE·09:33 AM
DescriptionSeverityWeakness
Aug 12, 2024
Data Sourced
via NVD·01:38 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-36461?
CVE-2024-36461 has a high severity rating due to the potential for memory manipulation leading to code execution.
2
How do I fix CVE-2024-36461?
To fix CVE-2024-36461, upgrade Zabbix to versions 6.0.31, 6.4.16, or 7.0.1 or later.
3
Which versions of Zabbix are affected by CVE-2024-36461?
CVE-2024-36461 affects Zabbix versions from 6.0.0 to 6.0.30, 6.4.0 to 6.4.15, and exclusively 7.0.0.
4
What impact can CVE-2024-36461 have on my system?
CVE-2024-36461 can allow an attacker to manipulate memory pointers, potentially leading to a system compromise.
5
Is there a workaround for CVE-2024-36461?
There are no specific workarounds documented for CVE-2024-36461; updating to a patched version is recommended.