CVE-2024-22121 — Improper Preservation of Permissions in Zabbix
Severity
6.1MEDIUMNVD
EPSS
0.0%
top 91.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 12
Description
A non-admin user can change or remove important features within the Zabbix Agent application, thus impacting the integrity and availability of the application.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:LExploitability: 1.8 | Impact: 4.2
Affected Packages3 packages
🔴Vulnerability Details
2GHSA▶
GHSA-mmh3-p6qg-xhw2: A non-admin user can change or remove important features within the Zabbix Agent application, thus impacting the integrity and availability of the app↗2024-08-12
OSV▶
CVE-2024-22121: A non-admin user can change or remove important features within the Zabbix Agent application, thus impacting the integrity and availability of the app↗2024-08-12
📋Vendor Advisories
1Debian▶
CVE-2024-22121: zabbix - A non-admin user can change or remove important features within the Zabbix Agent...↗2024