Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-22116

Опубликовано: 12 авг. 2024
Источник: debian
EPSS Низкий

Описание

An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default escaping for script parameters enabled this user ability to execute arbitrary code via the Ping script, thereby compromising infrastructure.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zabbixfixed1:7.0.0+dfsg-1package

Примечания

  • https://support.zabbix.com/browse/ZBX-25016

  • https://github.com/zabbix/zabbix/commit/afb3ab931d59af61e4f974634b85bcbed5a042b2 (7.0.0rc3)

  • https://github.com/zabbix/zabbix/commit/679e18f172fc1f9a78b19789fbbc52246871ff19 (7.0.1rc1)

  • https://github.com/zabbix/zabbix/commit/e6acaef1df1db44aaa9c1a0e1953a4da21425636 (7.0.1rc1)

  • https://github.com/zabbix/zabbix/commit/182e1a9d96dcd82de337b31dc1cbbd6b4b619281 (6.4.16rc1)

  • https://github.com/zabbix/zabbix/commit/a2dad304083387b8597ef1d67394f285b105f614 (6.4.16rc1)

EPSS

Процентиль: 75%
0.00925
Низкий

Связанные уязвимости

CVSS3: 9.9
ubuntu
около 1 года назад

An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default escaping for script parameters enabled this user ability to execute arbitrary code via the Ping script, thereby compromising infrastructure.

CVSS3: 9.9
nvd
около 1 года назад

An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default escaping for script parameters enabled this user ability to execute arbitrary code via the Ping script, thereby compromising infrastructure.

CVSS3: 9.9
github
около 1 года назад

An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default escaping for script parameters enabled this user ability to execute arbitrary code via the Ping script, thereby compromising infrastructure.

CVSS3: 9.9
fstec
около 1 года назад

Уязвимость компонента «Мониторинг хостов» универсальной системы мониторинга Zabbix, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.9
redos
7 месяцев назад

Уязвимость zabbix-agent

EPSS

Процентиль: 75%
0.00925
Низкий