CVE-2024-36460
published 2024-08-12CVE-2024-36460: The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.
PriorityP342high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.61%
45.5th percentile
The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zabbix | < zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye) | zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye) |
| zabbix | zabbix | — | — |
| zabbix | zabbix | >= 0 < 1:5.0.44+dfsg-1+deb11u1 | 1:5.0.44+dfsg-1+deb11u1 |
| zabbix | zabbix | >= 0 < 1:7.0.1+dfsg-1 | 1:7.0.1+dfsg-1 |
| zabbix | zabbix | >= 0 < 1:7.0.1+dfsg-1 | 1:7.0.1+dfsg-1 |
| zabbix | zabbix | 5,0,0 – 5.0.42 | — |
| zabbix | zabbix | 5.0.0 – 5.0.42 | — |
| zabbix | zabbix | 6.0.0 – 6.0.30 | — |
| zabbix | zabbix | 6.4.0 – 6.4.15 | — |
| zabbix | zabbix | 7.0.0alpha1 – 7.0.0rc2 | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
osv8.1HIGH
vendor_debian8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2024-36460: zabbix - The front-end audit log allows viewing of unprotected plaintext passwords, where...
vendor_debian·2024·CVSS 8.1
CVE-2024-36460 [HIGH] CVE-2024-36460: zabbix - The front-end audit log allows viewing of unprotected plaintext passwords, where...
The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.
Scope: local
bookworm: open
bullseye: resolved (fixed in 1:5.0.44+dfsg-1+deb11u1)
forky: resolved (fixed in 1:7.0.1+dfsg-1)
sid: resolved (fixed in 1:7.0.1+dfsg-1)
trixie: resolved (fixed in 1:7.0.1+dfsg-1)
OSV
CVE-2024-36460: The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text
osv·2024-08-12·CVSS 8.1
CVE-2024-36460 [HIGH] CVE-2024-36460: The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text
The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.
GHSA
GHSA-7w94-mp6m-pfq8: The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text
ghsa_unreviewed·2024-08-12
CVE-2024-36460 [HIGH] CWE-256 GHSA-7w94-mp6m-pfq8: The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text
The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-08-12
Published