CVE Vulnerabilities

CVE-2024-36460

Plaintext Storage of a Password

Published: Aug 12, 2024 | Modified: Dec 10, 2024
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.

Weakness

Storing a password in plaintext may result in a system compromise.

Affected Software

Name Vendor Start Version End Version
Zabbix Zabbix 5.0.0 (including) 5.0.42 (including)
Zabbix Zabbix 6.0.0 (including) 6.0.30 (including)
Zabbix Zabbix 6.4.0 (including) 6.4.15 (including)
Zabbix Zabbix 7.0.0 (including) 7.0.0 (including)
Zabbix Ubuntu trusty/esm *

Potential Mitigations

References