CVE-2024-42325

LOW

Zabbix - Info Disclosure

Title source: llm
STIX 2.1

Description

Zabbix API user.get returns all users that share common group with the calling user. This includes media and other information, such as login attempts, etc.

Scores

CVSS v3 3.5
EPSS 0.0010
EPSS Percentile 27.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-359
Status published
Products (1)
zabbix/zabbix 5.0.0 - 5.0.46
Published Apr 02, 2025
Tracked Since Feb 18, 2026