Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-42330


The HttpRequest object allows to get the HTTP headers from the server's response after sending the request. The problem is that the returned strings are created directly from the data returned by the server and are not correctly encoded for JavaScript. This allows to create internal strings that can be used to access hidden properties of objects.


Published

2024-11-27T12:15:21.007

Last Modified

2025-11-03T22:18:04.610

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.1 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-134

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application zabbix zabbix < 5.4.6 Yes
Application zabbix zabbix < 6.0.34 Yes
Application zabbix zabbix < 6.4.19 Yes
Application zabbix zabbix < 7.0.4 Yes

References