CVE Vulnerabilities

CVE-2024-36466

Authentication Bypass by Spoofing

Published: Nov 28, 2024 | Modified: Nov 28, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions.

Weakness

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Affected Software

Name Vendor Start Version End Version
Zabbix Ubuntu trusty/esm *
Zabbix Ubuntu upstream *

References