CVE Vulnerabilities

CVE-2021-46088

Published: Jan 27, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
NEGLIGIBLE
root.io logo minimus.io logo echo.ai logo

Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the Zabbix Admin role is able to run custom shell script on the application server in the context of the application user.

Affected Software

NameVendorStart VersionEnd Version
ZabbixZabbix4.0.0 (including)4.0.34 (including)
ZabbixZabbix4.2.0 (including)4.2.8 (including)
ZabbixZabbix4.4.0 (including)4.4.11 (including)
ZabbixZabbix5.0.0 (including)5.0.20 (including)
ZabbixUbuntubionic*
ZabbixUbuntufocal*
ZabbixUbuntuimpish*
ZabbixUbuntukinetic*
ZabbixUbuntulunar*
ZabbixUbuntumantic*
ZabbixUbuntuoracular*
ZabbixUbuntuplucky*
ZabbixUbuntutrusty*
ZabbixUbuntutrusty/esm*
ZabbixUbuntuxenial*

References