CVE-2024-36464
Severity CVSS v4.0:
Pending analysis
Type:
CWE-256
Plaintext Storage of a Password
Publication date:
27/11/2024
Last modified:
03/11/2025
Description
When exporting media types, the password is exported in the YAML in plain text. This appears to be a best practices type issue and may have no actual impact. The user would need to have permissions to access the media types and therefore would be expected to have access to these passwords.
Impact
Base Score 3.x
2.70
Severity 3.x
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* | 6.0.0 (including) | 6.0.30 (excluding) |
| cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* | 6.4.0 (including) | 6.4.15 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



