CVE-2024-36466
published 2024-11-28CVE-2024-36466: A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions.
PriorityP352high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.73%
50.2th percentile
A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zabbix | < zabbix 1:7.0.1+dfsg-1 (forky) | zabbix 1:7.0.1+dfsg-1 (forky) |
| zabbix | zabbix | — | — |
| zabbix | zabbix | >= 0 < 1:7.0.1+dfsg-1 | 1:7.0.1+dfsg-1 |
| zabbix | zabbix | >= 0 < 1:7.0.1+dfsg-1 | 1:7.0.1+dfsg-1 |
| zabbix | zabbix | >= 6.0.0 < 6.0.32 | 6.0.32 |
| zabbix | zabbix | 6.0.0 – 6.0.31 | — |
| zabbix | zabbix | >= 6.4.0 < 6.4.17 | 6.4.17 |
| zabbix | zabbix | 6.4.0 – 6.4.16 | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2024-36466: zabbix - A bug in the code allows an attacker to sign a forged zbx_session cookie, which ...
vendor_debian·2024·CVSS 8.8
CVE-2024-36466 [HIGH] CVE-2024-36466: zabbix - A bug in the code allows an attacker to sign a forged zbx_session cookie, which ...
A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions.
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 1:7.0.1+dfsg-1)
sid: resolved (fixed in 1:7.0.1+dfsg-1)
trixie: resolved (fixed in 1:7.0.1+dfsg-1)
OSV
CVE-2024-36466: A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions
osv·2024-11-28·CVSS 8.8
CVE-2024-36466 [HIGH] CVE-2024-36466: A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions
A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions.
GHSA
GHSA-23gg-m473-8fr9: A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions
ghsa_unreviewed·2024-11-28
CVE-2024-36466 [HIGH] CWE-290 GHSA-23gg-m473-8fr9: A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions
A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-28
Published