6.5

CVE-2024-36463

The implementation of atob in "Zabbix JS" allows to create a string with arbitrary content and use it to access internal properties of objects.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorZabbix
Product Zabbix
Default Statusunaffected
Version <= 5.0.42
Version 5.0.0
Status affected
Version <= 6.0.32
Version 6.0.0
Status affected
Version <= 6.4.17
Version 6.4.0
Status affected
Version <= 7.0.2
Version 7.0.0
Status affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.24% 0.473
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
security@zabbix.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-767 Access to Critical Private Variable via Public Method

The product defines a public method that reads or modifies a private variable.