CVE-2024-36463: High severity Zabbix Zabbix vulnerability
Published Nov 26, 2024
·Updated
The implementation of atob in "Zabbix JS" allows to create a string with arbitrary content and use it to access internal properties of objects.
Affected Software
4 affected components
Zabbix Zabbix>=5.0.0<5.0.43
Zabbix Zabbix>=6.0.0<6.0.33
Zabbix Zabbix>=6.4.0<6.4.18
Zabbix Zabbix>=7.0.0<7.0.3
Event History
Nov 26, 2024
CVE Published
via MITRE·03:06 PM
Data Sourced
via MITRE·03:06 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-36463?
CVE-2024-36463 has been classified with a high severity level due to its potential impact on internal object properties.
2
How do I fix CVE-2024-36463?
To fix CVE-2024-36463, update Zabbix to versions 5.0.43, 6.0.33, 6.4.18, or 7.0.3 or later.
3
Which versions of Zabbix are affected by CVE-2024-36463?
CVE-2024-36463 affects Zabbix versions 5.0.0 to 5.0.43, 6.0.0 to 6.0.33, 6.4.0 to 6.4.18, and 7.0.0 to 7.0.3.
4
What is the impact of CVE-2024-36463 on Zabbix?
The impact of CVE-2024-36463 allows an attacker to create a string with arbitrary content, leading to unauthorized access to internal properties of objects.
5
Is there a workaround for CVE-2024-36463 if I cannot update?
Currently, there are no documented workarounds for CVE-2024-36463, so updating is the recommended action.