The HttpRequest object allows to get the HTTP headers from the server's response after sending the request. The problem is that the returned strings are created directly from the data returned by the server and are not correctly encoded for JavaScript. This allows to create internal strings that can be used to access hidden properties of objects.
The HttpRequest object retrieves HTTP headers from the server response after sending a request. The returned strings are created directly from data received from the server without proper encoding for the JavaScript context (CWE-134 — format string). This makes it possible to create internal strings that can be used to gain access to hidden object properties. An attacker with administrative privileges can craft a server response containing malicious data in HTTP headers.
An attacker can gain access to hidden properties of JavaScript objects in the Zabbix context, which combined with the high privilege level resulting from the vulnerability scope (Scope: Changed, C/I/A: High) may lead to complete breach of system confidentiality, integrity, and availability.
Patches available from the vendor should be applied according to references (https://support.zabbix.com/browse/ZBX-25626). Users of Debian LTS distributions should apply updates described in the debian-lts-announce announcement from December 2024.
Zabbix products — versions indicated in vendor references (issue ZBX-25626); the vulnerability also affects Debian LTS packages according to the debian-lts-announce announcement.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HZabbix
APPZabbix5.0.0 – 5.4.6 (excl.)6.0.0 – 6.0.34 (excl.)6.4.0 – 6.4.19 (excl.)7.0.0 – 7.0.4 (excl.)
Related vulnerabilities
Zabbix SAML SSO — privilege escalation do konta administratora
SQL Injection w Zabbix – podatność w klasie CUser umożliwia eskalację uprawnień
Zabbix: modyfikacja wskaźników pamięci w silniku JavaScript (RCE/DoS)
Zabbix: RCE przez brak escapowania parametrów skryptu Ping
Zabbix Server — time-based blind SQL injection przez pole clientip