Information disclosure in Zabbix - CVE-2024-36469
Published: April 3, 2025
Vulnerability identifier: #VU106939
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-36469
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote attacker can enumerate users via Zabbix frontend login form and API.
Affected software
Zabbix
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
Fedora
zabbix-agent
zabbix-debugsource
zabbix-agent-debuginfo
zabbix6.0
zabbix
zabbix7.0
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
Fedora
zabbix-agent
zabbix-debugsource
zabbix-agent-debuginfo
zabbix6.0
zabbix
zabbix7.0
How to mitigate CVE-2024-36469
Install updates from vendor's website.
Zabbix - addressed in versions 5.0.46 rc1, 6.0.38 rc1, 7.0.9 rc1, 7.2.3 rc1
zabbix-agent - update to 4.0.12-4.45.1
zabbix-debugsource - update to 4.0.12-4.45.1
zabbix-agent-debuginfo - update to 4.0.12-4.45.1
zabbix6.0 - update to 6.0.39-1.el8
zabbix - addressed in versions 6.0.39-1.el9, 6.0.39-1.fc40, 7.0.11-1.fc41, 7.2.5-1.fc42
zabbix7.0 - addressed in versions 7.0.11-1.el8, 7.0.11-1.el9
zabbix-agent - update to 4.0.12-4.45.1
zabbix-debugsource - update to 4.0.12-4.45.1
zabbix-agent-debuginfo - update to 4.0.12-4.45.1
zabbix6.0 - update to 6.0.39-1.el8
zabbix - addressed in versions 6.0.39-1.el9, 6.0.39-1.fc40, 7.0.11-1.fc41, 7.2.5-1.fc42
zabbix7.0 - addressed in versions 7.0.11-1.el8, 7.0.11-1.el9