CVE-2024-36461
published 2024-08-12CVE-2024-36461: Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.
PriorityP345high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.76%
51.3th percentile
Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zabbix | < zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye) | zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye) |
| zabbix | zabbix | — | — |
| zabbix | zabbix | >= 0 < 1:5.0.44+dfsg-1+deb11u1 | 1:5.0.44+dfsg-1+deb11u1 |
| zabbix | zabbix | >= 0 < 1:7.0.1+dfsg-1 | 1:7.0.1+dfsg-1 |
| zabbix | zabbix | >= 0 < 1:7.0.1+dfsg-1 | 1:7.0.1+dfsg-1 |
| zabbix | zabbix | 6.0.0 – 6.0.30 | — |
| zabbix | zabbix | 6.4.0 – 6.4.15 | — |
| zabbix | zabbix | 7.0.0alpha1 – 7.0.0 | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3q27-8g46-2vwm: Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine
ghsa_unreviewed·2024-08-12
CVE-2024-36461 [CRITICAL] CWE-822 GHSA-3q27-8g46-2vwm: Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine
Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.
OSV
CVE-2024-36461: Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine
osv·2024-08-12·CVSS 8.8
CVE-2024-36461 [HIGH] CVE-2024-36461: Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine
Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.
Debian
CVE-2024-36461: zabbix - Within Zabbix, users have the ability to directly modify memory pointers in the ...
vendor_debian·2024·CVSS 9.1
CVE-2024-36461 [CRITICAL] CVE-2024-36461: zabbix - Within Zabbix, users have the ability to directly modify memory pointers in the ...
Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.
Scope: local
bookworm: open
bullseye: resolved (fixed in 1:5.0.44+dfsg-1+deb11u1)
forky: resolved (fixed in 1:7.0.1+dfsg-1)
sid: resolved (fixed in 1:7.0.1+dfsg-1)
trixie: resolved (fixed in 1:7.0.1+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-08-12
Published