CVE-2024-36469

Severity CVSS v4.0:
LOW
Type:
Unavailable / Other
Publication date:
02/04/2025
Last modified:
03/11/2025

Description

Execution time for an unsuccessful login differs when using a non-existing username compared to using an existing one.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* 5.0.0 (including) 5.0.46 (excluding)
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* 6.0.0 (including) 6.0.38 (excluding)
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* 7.0.0 (including) 7.0.9 (excluding)
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* 7.2.0 (including) 7.2.3 (excluding)