When exporting media types, the password is exported in the YAML in plain text. This appears to be a best practices type issue and may have no actual impact. The user would need to have permissions to access the media types and therefore would be expected to have access to these passwords.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-3984-1 | zabbix security update |
![]() |
EUVD-2024-36347 | When exporting media types, the password is exported in the YAML in plain text. This appears to be a best practices type issue and may have no actual impact. The user would need to have permissions to access the media types and therefore would be expected to have access to these passwords. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
Link | Providers |
---|---|
https://support.zabbix.com/browse/ZBX-25630 |
![]() ![]() |
History
Wed, 08 Oct 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Zabbix
Zabbix zabbix |
|
CPEs | cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* | |
Vendors & Products |
Zabbix
Zabbix zabbix |
Wed, 27 Nov 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | When exporting media types, the password is exported in the YAML in plain text. This appears to be a best practices type issue and may have no actual impact. The user would need to have permissions to access the media types and therefore would be expected to have access to these passwords. | |
Title | Media Types: Office365, SMTP passwords are unencrypted and visible in plaintext when exported | |
Weaknesses | CWE-256 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Zabbix
Published:
Updated: 2024-11-27T14:28:40.384Z
Reserved: 2024-05-28T11:21:24.946Z
Link: CVE-2024-36464

No data.

Status : Analyzed
Published: 2024-11-27T14:15:17.830
Modified: 2025-10-08T15:31:21.867
Link: CVE-2024-36464

No data.

No data.