Command Injection Affecting zabbix/zabbix package, versions [,5.0.43rc1) [6.0.0,6.0.30rc1) [6.4.0,6.4.16rc1) [7.0.0alpha1,7.0.0rc3)
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.04% (11th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-UNMANAGED-ZABBIXZABBIX-7659968
- published 9 Aug 2024
- disclosed 9 Aug 2024
- credit Maksim Tiukov
Introduced: 9 Aug 2024
CVE-2024-22122 Open this link in a new tabHow to fix?
Upgrade zabbix/zabbix
to version 5.0.43rc1, 6.0.30rc1, 6.4.16rc1, 7.0.0rc3 or higher.
Overview
Affected versions of this package are vulnerable to Command Injection of AT (GSM) commands by passing in a malicious Number via the web interface or directly on the server, when setting up an SMS number.