JS - Crash on unexpected HTTP server response (CVE-2024-42329)

XMLWordPrintable

    • Type: Defect (Security)
    • Resolution: Fixed
    • Priority: Trivial
    • 7.0.4rc1
    • Affects Version/s: None
    • Component/s: Server (S)
    • None

      The webdriver for the Browser object expects an error object to be initialized when the webdriver_session_query function fails. But this function can fail for various reasons without an error description and then the wd->error will be NULL and trying to read from it will result in a crash.

            Assignee:
            Zabbix Support Team
            Reporter:
            Vjaceslavs Bogdanovs
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: