CVE-2024-42330
published 2024-11-27CVE-2024-42330: The HttpRequest object allows to get the HTTP headers from the server's response after sending the request. The problem is that the returned strings are…
PriorityP350critical9.1CVSS 3.1
AVNACLPRHUINSCCHIHAH
EPSS
0.95%
57.3th percentile
The HttpRequest object allows to get the HTTP headers from the server's response after sending the request. The problem is that the returned strings are created directly from the data returned by the server and are not correctly encoded for JavaScript. This allows to create internal strings that can be used to access hidden properties of objects.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zabbix | < zabbix 1:5.0.45+dfsg-1+deb11u1 (bullseye) | zabbix 1:5.0.45+dfsg-1+deb11u1 (bullseye) |
| zabbix | zabbix | >= 0 < 1:5.0.45+dfsg-1+deb11u1 | 1:5.0.45+dfsg-1+deb11u1 |
| zabbix | zabbix | >= 0 < 1:7.0.5+dfsg-1 | 1:7.0.5+dfsg-1 |
| zabbix | zabbix | >= 0 < 1:7.0.5+dfsg-1 | 1:7.0.5+dfsg-1 |
| zabbix | zabbix | >= 5.0.0 < 5.4.6 | 5.4.6 |
| zabbix | zabbix | >= 6.0.0 < 6.0.34 | 6.0.34 |
| zabbix | zabbix | 6.0.0 – 6.0.33 | — |
| zabbix | zabbix | >= 6.4.0 < 6.4.19 | 6.4.19 |
| zabbix | zabbix | 6.4.0 – 6.4.18 | — |
| zabbix | zabbix | >= 7.0.0 < 7.0.4 | 7.0.4 |
| zabbix | zabbix | 7.0.0 – 7.0.3 | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
osv9.1CRITICAL
vendor_debian9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-42330: The HttpRequest object allows to get the HTTP headers from the server's response after sending the request
osv·2024-11-27·CVSS 9.1
CVE-2024-42330 [CRITICAL] CVE-2024-42330: The HttpRequest object allows to get the HTTP headers from the server's response after sending the request
The HttpRequest object allows to get the HTTP headers from the server's response after sending the request. The problem is that the returned strings are created directly from the data returned by the server and are not correctly encoded for JavaScript. This allows to create internal strings that can be used to access hidden properties of objects.
GHSA
GHSA-q4wv-f3rp-mjgr: The HttpRequest object allows to get the HTTP headers from the server's response after sending the request
ghsa_unreviewed·2024-11-27
CVE-2024-42330 [CRITICAL] CWE-134 GHSA-q4wv-f3rp-mjgr: The HttpRequest object allows to get the HTTP headers from the server's response after sending the request
The HttpRequest object allows to get the HTTP headers from the server's response after sending the request. The problem is that the returned strings are created directly from the data returned by the server and are not correctly encoded for JavaScript. This allows to create internal strings that can be used to access hidden properties of objects.
Debian
CVE-2024-42330: zabbix - The HttpRequest object allows to get the HTTP headers from the server's response...
vendor_debian·2024·CVSS 9.1
CVE-2024-42330 [CRITICAL] CVE-2024-42330: zabbix - The HttpRequest object allows to get the HTTP headers from the server's response...
The HttpRequest object allows to get the HTTP headers from the server's response after sending the request. The problem is that the returned strings are created directly from the data returned by the server and are not correctly encoded for JavaScript. This allows to create internal strings that can be used to access hidden properties of objects.
Scope: local
bookworm: open
bullseye: resolved (fixed in 1:5.0.45+dfsg-1+deb11u1)
forky: resolved (fixed in 1:7.0.5+dfsg-1)
sid: resolved (fixed in 1:7.0.5+dfsg-1)
trixie: resolved (fixed in 1:7.0.5+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-27
Published