User can view host count and other statistics without permission
CVE-2024-22114

4.3MEDIUM

Key Information:

Vendor

Zabbix

Status
Vendor
CVE Published:
12 August 2024

What is CVE-2024-22114?

A security flaw in Zabbix allows users without proper permissions to access sensitive information through the System Information Widget in the Global View Dashboard. This vulnerability enables unauthorized individuals to view host counts and associated statistics, impacting the confidentiality of system data. Organizations using vulnerable versions of Zabbix must take immediate action to secure their dashboard settings and prevent unauthorized access to sensitive host-related information.

Affected Version(s)

Zabbix 5,0,0 <= 5.0.42

Zabbix 6.0 <= 6.0.30

Zabbix 6.4.0 <= 6.4.15

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zabbix wants to thank Jayateertha G (jayateerthag) who submitted this report in HackerOne bug bounty platform
.