Zabbix vulnerable to critical SQL injection flaw
- December 2, 2024
- 0
Zabbix urges users to upgrade immediately due to a serious bug in the open source platform. The Zabbix monitoring platform is vulnerable to a critical error. CVE-2024-42327 allows
Zabbix urges users to upgrade immediately due to a serious bug in the open source platform. The Zabbix monitoring platform is vulnerable to a critical error. CVE-2024-42327 allows
Zabbix urges users to upgrade immediately due to a serious bug in the open source platform.
The Zabbix monitoring platform is vulnerable to a critical error. CVE-2024-42327 allows low-privilege users on the front end to escalate their privileges via SQL injection, potentially wreaking havoc. Other roles with API access can also exploit the error. Taking the severity into account, the CVSS score is 9.9.
A patch is now available. Zabbix urges users to install it immediately. The following editions of the open source platform are vulnerable to the error:
An upgrade to 6.0.32rc1, 6.4.17rc1 or 7.0.1rc1 brings relief.
SQL injections have been around forever and are easy to exploit. On the other hand, it is not that difficult for companies to eliminate such errors before the software goes into production. The American FBI and CISA therefore generally consider SQL injection bugs to be inexcusable.
Zabbix itself provides further details on its website. Now that the bug is publicly known, Zabbix administrators should take action quickly. Finally, a hacker who somehow obtains a user account’s login credentials can easily expand their access as long as the leak is not closed.
Source: IT Daily
As an experienced journalist and author, Mary has been reporting on the latest news and trends for over 5 years. With a passion for uncovering the stories behind the headlines, Mary has earned a reputation as a trusted voice in the world of journalism. Her writing style is insightful, engaging and thought-provoking, as she takes a deep dive into the most pressing issues of our time.