CVE-2024-42325: Excessive information returned by user.get
Published Apr 2, 2025
·Updated
Zabbix API user.get returns all users that share common group with the calling user. This includes media and other information, such as login attempts, etc.
Affected Software
5 affected components
Zabbix Zabbix API
Zabbix Zabbix>=5.0.0<5.0.46
Zabbix Zabbix>=6.0.0<6.0.38
Zabbix Zabbix>=7.0.0<7.0.9
Zabbix Zabbix>=7.2.0<7.2.3
Event History
Apr 2, 2025
CVE Published
via MITRE·06:12 AM
Data Sourced
via MITRE·06:12 AM
DescriptionWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-42325?
The severity of CVE-2024-42325 is classified as medium, indicating potential risks to user data.
2
How do I fix CVE-2024-42325?
To fix CVE-2024-42325, update to the latest version of Zabbix that addresses the vulnerability.
3
What kind of information is exposed by CVE-2024-42325?
CVE-2024-42325 exposes sensitive user information including media, login attempts, and other related data.
4
Which users are affected by CVE-2024-42325?
Users belonging to the same groups as the calling user can be affected by CVE-2024-42325 due to shared access.
5
Is CVE-2024-42325 a remote vulnerability?
Yes, CVE-2024-42325 can be exploited remotely through the Zabbix API.