CRITICAL🇵🇱 Wersja polska

CVE-2024-42330

CVSS 9.1v3.1pub. 2024-11-27upd. 2025-11-03

The HttpRequest object allows to get the HTTP headers from the server's response after sending the request. The problem is that the returned strings are created directly from the data returned by the server and are not correctly encoded for JavaScript. This allows to create internal strings that can be used to access hidden properties of objects.

🤖 AI Analysis
How it works

The HttpRequest object retrieves HTTP headers from the server response after sending a request. The returned strings are created directly from data received from the server without proper encoding for the JavaScript context (CWE-134 — format string). This makes it possible to create internal strings that can be used to gain access to hidden object properties. An attacker with administrative privileges can craft a server response containing malicious data in HTTP headers.

Impact

An attacker can gain access to hidden properties of JavaScript objects in the Zabbix context, which combined with the high privilege level resulting from the vulnerability scope (Scope: Changed, C/I/A: High) may lead to complete breach of system confidentiality, integrity, and availability.

Mitigation & patch

Patches available from the vendor should be applied according to references (https://support.zabbix.com/browse/ZBX-25626). Users of Debian LTS distributions should apply updates described in the debian-lts-announce announcement from December 2024.

Who is affected

Zabbix products — versions indicated in vendor references (issue ZBX-25626); the vulnerability also affects Debian LTS packages according to the debian-lts-announce announcement.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Zabbix

    APP
    Zabbix
    5.0.0 – 5.4.6 (excl.)6.0.0 – 6.0.34 (excl.)6.4.0 – 6.4.19 (excl.)7.0.0 – 7.0.4 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-23131CRITICAL9.1⚠ KEVPL ✓same product

Zabbix SAML SSO — privilege escalation do konta administratora

CVE-2024-42327CRITICAL9.9PL ✓same product

SQL Injection w Zabbix – podatność w klasie CUser umożliwia eskalację uprawnień

CVE-2024-36461CRITICAL9.1PL ✓same product

Zabbix: modyfikacja wskaźników pamięci w silniku JavaScript (RCE/DoS)

CVE-2024-22116CRITICAL9.9PL ✓same product

Zabbix: RCE przez brak escapowania parametrów skryptu Ping

CVE-2024-22120CRITICAL9.1PL ✓same product

Zabbix Server — time-based blind SQL injection przez pole clientip