Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3984-1 | zabbix security update |
EUVD |
EUVD-2024-39876 | The HttpRequest object allows to get the HTTP headers from the server's response after sending the request. The problem is that the returned strings are created directly from the data returned by the server and are not correctly encoded for JavaScript. This allows to create internal strings that can be used to access hidden properties of objects. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 03 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 08 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zabbix zabbix
|
|
| CPEs | cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zabbix zabbix
|
Wed, 27 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zabbix
Zabbix frontend |
|
| CPEs | cpe:2.3:a:zabbix:frontend:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zabbix
Zabbix frontend |
|
| Metrics |
ssvc
|
Wed, 27 Nov 2024 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The HttpRequest object allows to get the HTTP headers from the server's response after sending the request. The problem is that the returned strings are created directly from the data returned by the server and are not correctly encoded for JavaScript. This allows to create internal strings that can be used to access hidden properties of objects. | |
| Title | JS - Internal strings in HTTP headers | |
| Weaknesses | CWE-134 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Zabbix
Published:
Updated: 2025-11-03T22:04:43.106Z
Reserved: 2024-07-30T08:27:36.132Z
Link: CVE-2024-42330
Updated: 2024-11-27T15:13:36.029Z
Status : Modified
Published: 2024-11-27T12:15:21.007
Modified: 2025-11-03T22:18:04.610
Link: CVE-2024-42330
No data.
OpenCVE Enrichment
No data.
Debian DLA
EUVD