CVE-2024-36466
Zabbix Server vulnerability analysis and mitigation

Overview

CVE-2024-36466 is a security vulnerability affecting Zabbix software that was discovered and disclosed on November 28, 2024. The vulnerability allows an attacker to sign a forged zbx_session cookie, which can be exploited to gain unauthorized access with administrative permissions. This vulnerability specifically affects certain versions of Zabbix, including version 6.0.14 in Debian bookworm, while it has been fixed in versions 7.0.9 and later (Debian Tracker).

Technical details

The vulnerability stems from a code flaw related to session handling in Zabbix's frontend component, specifically when SSO (Single Sign-On) is being used. The vulnerable feature was introduced with commit 24e7ca3c792fe3581fdb39c3f7c914c6a4c92500 in version 6.0.0alpha1. The issue has been addressed through fixes implemented in versions 6.0.32rc1 and 7.0.1rc1 (Zabbix Support).

Impact

When successfully exploited, this vulnerability allows unauthorized users to gain administrative access to the Zabbix frontend, potentially compromising the entire monitoring system's security. The attacker can achieve this by manipulating the zbx_session cookie to obtain administrator-level permissions (NVD).

Mitigation and workarounds

The vulnerability has been fixed in multiple versions including 6.0.32rc1, 6.4.17rc1, and 7.0.1rc1. Users are advised to upgrade to these or later versions. The fixes were implemented through commits 6e39148b7361312f730d87e4438f692a2c39d07e (7.0.1rc1) and 48e7615d1e1e3a5f543505cc6cb0a5564a655b58 (6.0.32rc1) (Debian Tracker).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
David EstlickCISO
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
Adam FletcherChief Security Officer
“We know that if Wiz identifies something as critical, it actually is.”
Greg PoniatowskiHead of Threat and Vulnerability Management