Zabbix
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*
- >= 6.0.0, <= 6.0.40
- >= 7.0.0, <= 7.0.17
- >= 7.2.0, <= 7.2.11
- >= 7.4.0, <= 7.4.1
A vulnerability exists in Zabbix that allows regular users, without permission to access the Monitoring -> Problems view, to invoke the problem.view.refresh action. This action retrievals a list of active problems, indicating an insufficient permission check.
Exploitation of this vulnerability could lead to unauthorized access to active problem data, allowing users to view issues they should not have permission to access.
Users can update to Zabbix versions 6.0.41, 7.0.18, 7.2.12, or 7.4.2 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.