CVE-2024-42325: Zabbix

Low severity, CVSS 3.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Zabbix API user.get returns all users that share common group with the calling user. This includes media and other information, such as login attempts, etc.

Affected products

  • Zabbix Zabbix: from 5.0.0, before 5.0.46 (fixed in 5.0.46); from 6.0.0, before 6.0.38 (fixed in 6.0.38); from 7.0.0, before 7.0.9 (fixed in 7.0.9); from 7.2.0, before 7.2.3 (fixed in 7.2.3)

Published 2025-04-02. Last modified 2026-06-17.