CVE-2024-42328: Zabbix

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

When the webdriver for the Browser object downloads data from a HTTP server, the data pointer is set to NULL and is allocated only in curl_write_cb when receiving data. If the server's response is an empty document, then wd->data in the code below will remain NULL and an attempt to read from it will result in a crash.

Affected products

  • Zabbix Zabbix: from 7.0.0, before 7.0.4 (fixed in 7.0.4)

Published 2024-11-27. Last modified 2026-06-17.