CVE-2024-22117: Zabbix

Low severity, CVSS 2.2. EPSS: 0.5% chance of exploitation in the next 30 days.

When a URL is added to the map element, it is recorded in the database with sequential IDs. Upon adding a new URL, the system retrieves the last sysmapelementurlid value and increments it by one. However, an issue arises when a user manually changes the sysmapelementurlid value by adding sysmapelementurlid + 1. This action prevents others from adding URLs to the map element.

Affected products

  • Zabbix Zabbix: from 5.0.0, before 5.0.44 (fixed in 5.0.44); from 6.0.0, before 6.0.34 (fixed in 6.0.34); from 6.4.0, before 6.4.19 (fixed in 6.4.19); from 7.0.0, before 7.0.4 (fixed in 7.0.4)

Published 2024-11-26. Last modified 2026-06-17.