CVE-2024-36463: Zabbix

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

The implementation of atob in "Zabbix JS" allows to create a string with arbitrary content and use it to access internal properties of objects.

Affected products

  • Zabbix Zabbix: from 5.0.0, before 5.0.43 (fixed in 5.0.43); from 6.0.0, before 6.0.33 (fixed in 6.0.33); from 6.4.0, before 6.4.18 (fixed in 6.4.18); from 7.0.0, before 7.0.3 (fixed in 7.0.3)

Published 2024-11-26. Last modified 2026-06-17.