CVE-2024-36464: Zabbix

Low severity, CVSS 2.7. EPSS: 0.6% chance of exploitation in the next 30 days.

When exporting media types, the password is exported in the YAML in plain text. This appears to be a best practices type issue and may have no actual impact. The user would need to have permissions to access the media types and therefore would be expected to have access to these passwords.

Affected products

  • Zabbix Zabbix: from 6.0.0, before 6.0.30 (fixed in 6.0.30); from 6.4.0, before 6.4.15 (fixed in 6.4.15)

Published 2024-11-27. Last modified 2026-06-17.