User can view host count and other statistics without permission
CVE-2024-22114
4.3MEDIUM
What is CVE-2024-22114?
A security flaw in Zabbix allows users without proper permissions to access sensitive information through the System Information Widget in the Global View Dashboard. This vulnerability enables unauthorized individuals to view host counts and associated statistics, impacting the confidentiality of system data. Organizations using vulnerable versions of Zabbix must take immediate action to secure their dashboard settings and prevent unauthorized access to sensitive host-related information.
Affected Version(s)
Zabbix 5,0,0 <= 5.0.42
Zabbix 6.0 <= 6.0.30
Zabbix 6.4.0 <= 6.4.15
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Zabbix wants to thank Jayateertha G (jayateerthag) who submitted this report in HackerOne bug bounty platform