First published: Wed Apr 02 2025(Updated: )
Zabbix API user.get returns all users that share common group with the calling user. This includes media and other information, such as login attempts, etc.
Credit: security@zabbix.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zabbix |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-42325 is classified as medium, indicating potential risks to user data.
To fix CVE-2024-42325, update to the latest version of Zabbix that addresses the vulnerability.
CVE-2024-42325 exposes sensitive user information including media, login attempts, and other related data.
Users belonging to the same groups as the calling user can be affected by CVE-2024-42325 due to shared access.
Yes, CVE-2024-42325 can be exploited remotely through the Zabbix API.