CVE-2024-22119

NameCVE-2024-22119
DescriptionThe cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
zabbix (PTS)jessie, jessie (lts)1:2.2.23+dfsg-0+deb8u7vulnerable
stretch (security)1:3.0.32+dfsg-0+deb9u3vulnerable
stretch (lts), stretch1:3.0.32+dfsg-0+deb9u6vulnerable
buster1:4.0.4+dfsg-1vulnerable
buster (security)1:4.0.4+dfsg-1+deb10u4vulnerable
bullseye1:5.0.8+dfsg-1vulnerable
bookworm1:6.0.14+dfsg-1vulnerable
sid1:6.0.29+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
zabbixsource(unstable)1:6.0.24+dfsg-1

Notes

https://support.zabbix.com/browse/ZBX-24070
https://git.zabbix.com/projects/ZBX/repos/zabbix/commits/aec9ebf575e6c62b5397f267ae5353b121a91262 (6.0.24rc1)
https://git.zabbix.com/projects/ZBX/repos/zabbix/commits/62a62b1b7f07a4a7cf249bef05968bb0eef1cfb2 (5.0.40rc1)

Search for package or bug name: Reporting problems