Information disclosure in Zabbix - CVE-2024-42325

 

Information disclosure in Zabbix - CVE-2024-42325

Published: April 3, 2025


Vulnerability identifier: #VU106937
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-42325
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to potentially sensitive information.

The vulnerability exists due to software returns the entire user list via the user.get API method. A remote user can gain access to sensitive personal information.


Affected software

Zabbix
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
Fedora
zabbix-agent
zabbix-debugsource
zabbix-agent-debuginfo
zabbix6.0
zabbix
zabbix7.0

How to mitigate CVE-2024-42325

Install updates from vendor's website.

Zabbix - addressed in versions 5.0.46 rc1, 6.0.38 rc1, 7.0.9 rc1, 7.2.3 rc1
zabbix-agent - update to 4.0.12-4.45.1
zabbix-debugsource - update to 4.0.12-4.45.1
zabbix-agent-debuginfo - update to 4.0.12-4.45.1
zabbix6.0 - update to 6.0.39-1.el8
zabbix - addressed in versions 6.0.39-1.el9, 6.0.39-1.fc40, 7.0.11-1.fc41, 7.2.5-1.fc42
zabbix7.0 - addressed in versions 7.0.11-1.el8, 7.0.11-1.el9

External References

Related Security Bulletins