Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the "Zabbix Admin" role is able to run custom shell script on the application server in the context of the application user.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/paalbra/zabbix-zbxsec-7 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-01-27T15:43:42
Updated: 2024-08-04T05:02:10.184Z
Reserved: 2022-01-03T00:00:00
Link: CVE-2021-46088
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2022-01-27T16:15:07.777
Modified: 2022-02-02T17:00:35.513
Link: CVE-2021-46088
Redhat
No data.