DEBIAN-CVE-2024-42327

Source
https://security-tracker.debian.org/tracker/CVE-2024-42327
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-42327.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2024-42327
Upstream
Published
2024-11-27T12:15:20.640Z
Modified
2026-03-17T02:45:44.321735Z
Severity
  • 9.9 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is being called from the CUser.get function which is available for every user who has API access.

References

Affected packages

Debian:12 / zabbix

Package

Name
zabbix
Purl
pkg:deb/debian/zabbix?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:6.*
1:6.0.14+dfsg-1
1:6.0.23+dfsg-1~bpo12+1
1:6.0.23+dfsg-1
1:6.0.24+dfsg-1
1:6.0.25+dfsg-1
1:6.0.29+dfsg-1
1:7.*
1:7.0.0+dfsg-1
1:7.0.0+dfsg-2~bpo12+1
1:7.0.0+dfsg-2
1:7.0.1+dfsg-1~bpo12+1
1:7.0.1+dfsg-1
1:7.0.2+dfsg-1~bpo12+1
1:7.0.2+dfsg-1
1:7.0.3+dfsg-1
1:7.0.5+dfsg-1~bpo12+1
1:7.0.5+dfsg-1
1:7.0.6+dfsg-1
1:7.0.9+dfsg-1~bpo12+1
1:7.0.9+dfsg-1
1:7.0.10+dfsg-1
1:7.0.10+dfsg-2
1:7.0.22+dfsg-1~bpo13+1
1:7.0.22+dfsg-1~deb13u1
1:7.0.22+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-42327.json"

Debian:13 / zabbix

Package

Name
zabbix
Purl
pkg:deb/debian/zabbix?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:7.0.1+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-42327.json"

Debian:14 / zabbix

Package

Name
zabbix
Purl
pkg:deb/debian/zabbix?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:7.0.1+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-42327.json"