
Cloud Vulnerability DB
A community-led vulnerabilities database
A critical security vulnerability (CVE-2024-22120) has been identified in Zabbix, an open-source IT infrastructure monitoring tool. The vulnerability affects versions from 6.0.0 to 6.4.12 and 7.0.0alpha1 to 7.0.0beta1, with a CVSS score of 9.1. The flaw was discovered in the server's audit logging mechanism where the 'clientip' field is not properly sanitized, allowing for time-based blind SQL injection attacks (SecurityOnline).
The vulnerability resides in the audit.c file, specifically within the zbx_auditlog_global_script function. When the Zabbix server executes commands for configured scripts, it creates an audit entry in the 'Audit Log'. The flaw exists because the 'clientip' field is not sanitized before being used in SQL queries, making it possible to inject malicious SQL commands. The vulnerability has been assigned a CVSS v3.1 base score of 9.1 (Critical) with the vector string CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H (NVD, Zabbix Support).
The exploitation of this vulnerability allows attackers to dump any values from the database, including sensitive information. It enables privilege escalation from a regular user to an admin level, significantly compromising the security and integrity of the monitored IT infrastructure. In certain scenarios, successful exploitation could potentially lead to remote code execution (RCE) (SecurityOnline).
The vulnerability can be exploited through time-based blind SQL injection techniques. An attacker with access to a low-privileged user account that has permission to run commands against at least one host can potentially exploit this vulnerability. The exploitation process involves extracting session information and utilizing the unsanitized 'clientip' field to inject malicious SQL queries (Zabbix Support).
Zabbix has released patches to address the vulnerability in versions 6.0.28rc1, 6.4.13rc1, and 7.0.0beta2. Organizations using affected versions should immediately upgrade to these patched versions. Additional security measures such as implementing web application firewalls (WAFs) and intrusion detection systems (IDS) can provide additional protection (SecurityOnline).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."