cbcvebase.
CVE-2024-42330
published 2024-11-27

CVE-2024-42330: The HttpRequest object allows to get the HTTP headers from the server's response after sending the request. The problem is that the returned strings are…

PriorityP350critical9.1CVSS 3.1
AVNACLPRHUINSCCHIHAH
EPSS
0.95%
57.3th percentile
The HttpRequest object allows to get the HTTP headers from the server's response after sending the request. The problem is that the returned strings are created directly from the data returned by the server and are not correctly encoded for JavaScript. This allows to create internal strings that can be used to access hidden properties of objects.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianzabbix< zabbix 1:5.0.45+dfsg-1+deb11u1 (bullseye)zabbix 1:5.0.45+dfsg-1+deb11u1 (bullseye)
zabbixzabbix>= 0 < 1:5.0.45+dfsg-1+deb11u11:5.0.45+dfsg-1+deb11u1
zabbixzabbix>= 0 < 1:7.0.5+dfsg-11:7.0.5+dfsg-1
zabbixzabbix>= 0 < 1:7.0.5+dfsg-11:7.0.5+dfsg-1
zabbixzabbix>= 5.0.0 < 5.4.65.4.6
zabbixzabbix>= 6.0.0 < 6.0.346.0.34
zabbixzabbix6.0.0 – 6.0.33
zabbixzabbix>= 6.4.0 < 6.4.196.4.19
zabbixzabbix6.4.0 – 6.4.18
zabbixzabbix>= 7.0.0 < 7.0.47.0.4
zabbixzabbix7.0.0 – 7.0.3

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
osv9.1CRITICAL
vendor_debian9.1CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.