CVE Vulnerabilities

CVE-2024-36463

Access to Critical Private Variable via Public Method

Published: Nov 26, 2024 | Modified: Oct 08, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The implementation of atob in Zabbix JS allows to create a string with arbitrary content and use it to access internal properties of objects.

Weakness

The product defines a public method that reads or modifies a private variable.

Affected Software

Name Vendor Start Version End Version
Zabbix Zabbix 5.0.0 (including) 5.0.43 (excluding)
Zabbix Zabbix 6.0.0 (including) 6.0.33 (excluding)
Zabbix Zabbix 6.4.0 (including) 6.4.18 (excluding)
Zabbix Zabbix 7.0.0 (including) 7.0.3 (excluding)
Zabbix Ubuntu focal *
Zabbix Ubuntu oracular *
Zabbix Ubuntu trusty/esm *
Zabbix Ubuntu upstream *

Potential Mitigations

References