CVE-2024-42331 | Zabbix up to 7.0.3 Duktape JavaScript Engine browser.c es_browser_ctor use after free (Nessus ID 212155)
A vulnerability categorized as problematic has been discovered in Zabbix up to 7.0.3. Affected is the function es_browser_ctor in the library src/libs/zbxembed/browser.c of the component Duktape JavaScript Engine. Executing manipulation can lead to use after free.
This vulnerability is tracked as CVE-2024-42331. The attack is restricted to local execution. No exploit exists.
It is advisable to upgrade the affected component.