Resource management error in Zabbix - CVE-2024-22117

 

Resource management error in Zabbix - CVE-2024-22117

Published: December 5, 2024


Vulnerability identifier: #VU101288
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-22117
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disable map feature.

The vulnerability exists due to improper handling of map element identifiers when adding a new URL. A remote user can increment the sysmapelementurlid value by 1 for an existing map element and prevent other users from adding new URLs.


Affected software

Zabbix
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
zabbix-agent-debuginfo
zabbix-agent
zabbix-debugsource

How to mitigate CVE-2024-22117

Install updates from vendor's website.

Zabbix - addressed in versions 5.0.44 rc1, 6.0.34 rc1, 6.4.19 rc1, 7.0.4 rc1
zabbix-agent-debuginfo - update to 4.0.12-4.32.1
zabbix-agent - update to 4.0.12-4.32.1
zabbix-debugsource - update to 4.0.12-4.32.1

External References

Related Security Bulletins