A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions.
[ { "signature_version": "v1", "target": { "file": "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java" }, "source": "https://github.com/zabbix/zabbix/commit/e0ebc610bbe07feec683b36b33b0c7c54d4dfa51", "digest": { "line_hashes": [ "268532432675997961382533109683550991275", "77468328968705158713064176216215297941", "242617437909076284338012963993674069245", "53988357087650554977707365843443920215", "128232534528403919384584568266563623737", "8192478687897789813459981120771879298" ], "threshold": 0.9 }, "deprecated": false, "id": "CVE-2024-36466-304bfe13", "signature_type": "Line" } ]