CVE Vulnerabilities

CVE-2021-46088

Published: Jan 27, 2022 | Modified: Feb 02, 2022
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the Zabbix Admin role is able to run custom shell script on the application server in the context of the application user.

Affected Software

Name Vendor Start Version End Version
Zabbix Zabbix 4.0.0 (including) 4.0.34 (including)
Zabbix Zabbix 4.2.0 (including) 4.2.8 (including)
Zabbix Zabbix 4.4.0 (including) 4.4.11 (including)
Zabbix Zabbix 5.0.0 (including) 5.0.20 (including)

References