PT-2014-4290 · Zabbix+1 · Zabbix+1

Vitaly Shupak

·

Publicado

2014-02-13

·

Atualizado

2014-05-09

·

CVE-2014-1682

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Zabbix versions prior to 1.8.20rc1 Zabbix versions 2.0.x prior to 2.0.11rc1 Zabbix versions 2.2.x prior to 2.2.2rc1
Description The issue allows remote authenticated users to spoof arbitrary users via the user name in a "user.login" request.
Recommendations For versions prior to 1.8.20rc1, update to version 1.8.20rc1 or later. For versions 2.0.x prior to 2.0.11rc1, update to version 2.0.11rc1 or later. For versions 2.2.x prior to 2.2.2rc1, update to version 2.2.2rc1 or later.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1190
CVE-2014-1682
MGASA-2014-0095

Produtos afetados

Alt Linux
Zabbix