PT-2019-5822 · Zabbix+1 · Zabbix+1

Published

2018-10-05

·

Updated

2023-10-21

·

CVE-2019-17382

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Zabbix versions prior to 4.4
Description An issue was discovered in "zabbix.php?action=dashboard.view&dashboardid=1" that allows an attacker to bypass the login page and access the dashboard page anonymously. The attacker can then create a Dashboard, Report, Screen, or Map without any username/password. All created elements are accessible by other users and by an admin. The vulnerability is related to bypassing authorization using a user-controlled key, which can allow a remote attacker to access the dashboard page and create elements.
Recommendations For Zabbix versions prior to 4.4, consider disabling access to the "zabbix.php?action=dashboard.view&dashboardid=1" endpoint until a patch is available. Restrict access to the dashboard page to minimize the risk of exploitation. Avoid using the dashboardid parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

IDOR

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2422
ALT-PU-2019-1862
ALT-PU-2019-3069
ALT-PU-2020-1083
ALT-PU-2020-3446
ALT-PU-2021-1587
ALT-PU-2021-2018
ALT-PU-2021-2582
ALT-PU-2021-2668
ALT-PU-2021-3617
ALT-PU-2022-1975
ALT-PU-2022-2499
ALT-PU-2023-6268
BDU:2021-03179
CVE-2019-17382
DLA-3538-1
DLA-3538-2

Affected Products

Alt Linux
Zabbix