Zabbix 5.4
Zabbix 5.4
The Zabbix 5.4 reached end of service life on Mar 31, 2022 — Zabbix no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.
24/7 engineers own your Zabbix 5.4 incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- zabbix
- release
- 5.4
- product Label
- Zabbix
- release Label
- 5.4
- codename
- lts
- latest Version
- 5.4.12
- release Date
- 2021-05-17
- maintained
- source Url
- https://endoflife.date/zabbix
Lifecycle Dates
- End of Service Life
- Mar 31, 2022
- Last OEM Support
- Feb 28, 2022
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Zabbix 5.4 — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Zabbix 5.4?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Zabbix 5.4 when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Zabbix 5.4 Support: Frequently Asked Questions
Is the Zabbix 5.4 still supported?
Zabbix ended support for the Zabbix 5.4 on Mar 31, 2022 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.
When is the Zabbix 5.4 end of service life (EOSL) date?
Zabbix lists the end of service life for the Zabbix 5.4 as Mar 31, 2022.
Can I keep using the Zabbix 5.4 after its EOSL date?
Yes. EOSL means Zabbix stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Zabbix 5.4 cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Zabbix 5.4
6 published CVEs affect the Zabbix 5.4, including 2 rated critical or high severity. Zabbix no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2024-42330 | CRITICAL | 9.1 | Nov 27, 2024 | The HttpRequest object allows to get the HTTP headers from the server's response after sending the request. The problem is that the returned strings are created directly from the data returned by the server and are not correctly encoded for JavaScript. This allows to create internal strings that can be used to access hidden properties of objects. |
| CVE-2022-23131 | CRITICAL | 9.1 | Jan 13, 2022 | In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and gain admin access to Zabbix Frontend. To perform the attack, SAML authentication is required to be enabled and the actor has to know the username of Zabbix user (or use the guest account, which is disabled by default). |
| CVE-2022-23133 | MEDIUM | 6.3 | Jan 13, 2022 | An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored by an authenticated malicious actor and other users try to search for groups during new host creation, the XSS payload will fire and the actor can steal session cookies and perform session hijacking to impersonate users or take over their accounts. |
| CVE-2023-29451 | MEDIUM | 4.7 | Jul 13, 2023 | Specially crafted string can cause a buffer overrun in the JSON parser library leading to a crash of the Zabbix Server or a Zabbix Proxy. |
| CVE-2022-23134 | LOW | 3.7 | Jan 13, 2022 | After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend. |
| CVE-2022-23132 | LOW | 3.3 | Jan 13, 2022 | During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix Proxy or Server processes can bypass file read, write and execute permissions check on the file system level |