CVE Vulnerabilities

CVE-2021-46088

Published: Jan 27, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
NEGLIGIBLE

Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the Zabbix Admin role is able to run custom shell script on the application server in the context of the application user.

Affected Software

Name Vendor Start Version End Version
Zabbix Zabbix 4.0.0 (including) 4.0.34 (including)
Zabbix Zabbix 4.2.0 (including) 4.2.8 (including)
Zabbix Zabbix 4.4.0 (including) 4.4.11 (including)
Zabbix Zabbix 5.0.0 (including) 5.0.20 (including)
Zabbix Ubuntu bionic *
Zabbix Ubuntu impish *
Zabbix Ubuntu kinetic *
Zabbix Ubuntu lunar *
Zabbix Ubuntu mantic *
Zabbix Ubuntu trusty *
Zabbix Ubuntu trusty/esm *
Zabbix Ubuntu xenial *

References