CVE-2024-42325

Published Apr 2, 2025

Last updated 7 months ago

Overview

Description
Zabbix API user.get returns all users that share common group with the calling user. This includes media and other information, such as login attempts, etc.
Source
security@zabbix.com
NVD status
Modified
Products
zabbix

Risk scores

CVSS 4.0

Type
Secondary
Base score
2.1
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
LOW

CVSS 3.1

Type
Primary
Base score
3.5
Impact score
1.4
Exploitability score
2.1
Vector string
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity
LOW

Weaknesses

security@zabbix.com
CWE-359

Social media

Hype score
Not currently trending

Configurations