CVE-2024-36460
12.08.2024, 13:38
The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.Enginsight
Vendor | Product | Version |
---|---|---|
zabbix | zabbix | 5.0.0 ≤ 𝑥 ≤ 5.0.42 |
zabbix | zabbix | 6.0.0 ≤ 𝑥 ≤ 6.0.30 |
zabbix | zabbix | 6.4.0 ≤ 𝑥 ≤ 6.4.15 |
zabbix | zabbix | 7.0.0 |
𝑥
= Vulnerable software versions

Debian Releases
Common Weakness Enumeration
- CWE-256 - Plaintext Storage of a PasswordStoring a password in plaintext may result in a system compromise.
- CWE-522 - Insufficiently Protected CredentialsThe product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.