| Name | CVE-2024-22119 | 
| Description | The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section. | 
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) | 
| References | DLA-3798-1, DLA-3909-1 | 
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status | 
|---|
| zabbix (PTS) | bullseye | 1:5.0.8+dfsg-1 | vulnerable | 
|  | bullseye (security) | 1:5.0.46+dfsg-1+deb11u1 | fixed | 
|  | bookworm | 1:6.0.14+dfsg-1 | vulnerable | 
|  | forky, sid, trixie | 1:7.0.10+dfsg-2 | fixed | 
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs | 
|---|
| zabbix | source | buster | 1:4.0.4+dfsg-1+deb10u5 |  | DLA-3798-1 |  | 
| zabbix | source | bullseye | 1:5.0.44+dfsg-1+deb11u1 |  | DLA-3909-1 |  | 
| zabbix | source | (unstable) | 1:6.0.24+dfsg-1 |  |  |  | 
Notes
https://support.zabbix.com/browse/ZBX-24070
Introduced by: https://git.zabbix.com/projects/ZBX/repos/zabbix/commits/d5b73ddafc2b91376c0d74027b5f727cea6f9c29 (4.0.0alpha1)
Fixed by: https://git.zabbix.com/projects/ZBX/repos/zabbix/commits/aec9ebf575e6c62b5397f267ae5353b121a91262 (6.0.24rc1)
Fixed by: https://git.zabbix.com/projects/ZBX/repos/zabbix/commits/62a62b1b7f07a4a7cf249bef05968bb0eef1cfb2 (5.0.40rc1)