Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate application usernames based on the variability of server responses (e.g., the "Login name or password is incorrect" and "No permissions for system access" messages, or just blocking for a number of seconds). This affects both api_jsonrpc.php and index.php.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade zabbix | Apr 23, 2021 | Aug 17, 2019 |
| Ubuntu | — | Upgrade zabbix-agent (Ubuntu Pro)Upgrade zabbix-server-mysql (Ubuntu Pro)Upgrade zabbix-frontend-php (Ubuntu Pro)Upgrade zabbix-proxy-pgsql (Ubuntu Pro)Upgrade zabbix-java-gateway (Ubuntu Pro)Upgrade zabbix-proxy-mysql (Ubuntu Pro)Upgrade zabbix-proxy-sqlite3 (Ubuntu Pro)Upgrade zabbix-server-pgsql (Ubuntu Pro) | Mar 22, 2023 | Aug 17, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub