Information disclosure in Zabbix - CVE-2024-36469

 

Information disclosure in Zabbix - CVE-2024-36469

Published: April 3, 2025


Vulnerability identifier: #VU106939
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-36469
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application. A remote attacker can enumerate users via Zabbix frontend login form and API.


Affected software

Zabbix
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
Fedora
zabbix-agent
zabbix-debugsource
zabbix-agent-debuginfo
zabbix6.0
zabbix
zabbix7.0

How to mitigate CVE-2024-36469

Install updates from vendor's website.

Zabbix - addressed in versions 5.0.46 rc1, 6.0.38 rc1, 7.0.9 rc1, 7.2.3 rc1
zabbix-agent - update to 4.0.12-4.45.1
zabbix-debugsource - update to 4.0.12-4.45.1
zabbix-agent-debuginfo - update to 4.0.12-4.45.1
zabbix6.0 - update to 6.0.39-1.el8
zabbix - addressed in versions 6.0.39-1.el9, 6.0.39-1.fc40, 7.0.11-1.fc41, 7.2.5-1.fc42
zabbix7.0 - addressed in versions 7.0.11-1.el8, 7.0.11-1.el9

External References

Related Security Bulletins