2024-12-08 03:06:42 +00:00

60 lines
2.0 KiB
JSON

{
"id": "CVE-2024-36464",
"sourceIdentifier": "security@zabbix.com",
"published": "2024-11-27T14:15:17.830",
"lastModified": "2024-11-27T14:15:17.830",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "When exporting media types, the password is exported in the YAML in plain text. This appears to be a best practices type issue and may have no actual impact. The user would need to have permissions to access the media types and therefore would be expected to have access to these passwords."
},
{
"lang": "es",
"value": "Al exportar tipos de medios, la contrase\u00f1a se exporta en el YAML en texto plano. Esto parece ser un problema de tipo de mejores pr\u00e1cticas y es posible que no tenga un impacto real. El usuario necesitar\u00eda tener permisos para acceder a los tipos de medios y, por lo tanto, se esperar\u00eda que tuviera acceso a estas contrase\u00f1as."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "security@zabbix.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
"baseScore": 2.7,
"baseSeverity": "LOW",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "HIGH",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 1.2,
"impactScore": 1.4
}
]
},
"weaknesses": [
{
"source": "security@zabbix.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-256"
}
]
}
],
"references": [
{
"url": "https://support.zabbix.com/browse/ZBX-25630",
"source": "security@zabbix.com"
}
]
}