CVE-2024-42330
The HttpRequest object allows to get the HTTP headers from the server's response after sending the request. The problem is that the returned strings are created directly from the data returned by the server and are not correctly encoded for JavaScript. This allows to create internal strings that can be used to access hidden properties of objects.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.95%
- CWE
- CWE-134
- Published
- 2024-11-27
- Last modified
- 2026-03-13
Affected products
- Zabbix Zabbix
- Zabbix Zabbix
- Zabbix Zabbix
Weakness type
Related vulnerabilities
- CVE-2026-69395 — Active Directory Certificate Services (AD CS) Information Disclosure Vulnerability
- CVE-2026-16821 — Vulnerabilities in IBM AIX and PowerVM VIOS
- CVE-2026-81574 — Format String Vulnerability in Logger
- CVE-2026-63073 — Untrusted Sender DN Used as Format String in CMP Response Validation
- CVE-2026-17136 — Vulnerabilities in IBM AIX and PowerVM VIOS
- CVE-2026-68553 — Coturn: Format String Injection via TURN USERNAME/REALM into hiredis Redis Command
- CVE-2026-15961 — Power System Information Disclosure
- CVE-2026-12004 — Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access