PT-2021-7704 · Zabbix+3 · Zabbix+3

Rostislav Palivoda

·

Published

2019-05-20

·

Updated

2023-04-12

·

CVE-2021-27927

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zabbix versions 4.0.x through 4.0.28rc1 Zabbix versions 5.0.0alpha1 through 5.0.10rc1 Zabbix versions 5.2.x through 5.2.6rc1 Zabbix versions 5.4.0alpha1 through 5.4.0beta2
Description The issue is related to a lack of CSRF protection mechanism in the CControllerAuthenticationUpdate controller, which calls diableSIDValidation inside the init() method. This allows a remote attacker to access confidential data, compromise its integrity, and cause a denial of service. The attacker does not need to know the Zabbix user's login credentials but must know the correct Zabbix URL and contact information of an existing user with sufficient privileges.
Recommendations For Zabbix versions 4.0.x through 4.0.28rc1, update to version 4.0.28rc1 or later. For Zabbix versions 5.0.0alpha1 through 5.0.10rc1, update to version 5.0.10rc1 or later. For Zabbix versions 5.2.x through 5.2.6rc1, update to version 5.2.6rc1 or later. For Zabbix versions 5.4.0alpha1 through 5.4.0beta2, update to version 5.4.0beta2 or later. As a temporary workaround, consider restricting access to the CControllerAuthenticationUpdate controller until a patch is available. Avoid using the diableSIDValidation function inside the init() method in the affected API endpoint until the issue is resolved.

Fix

CSRF

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1862
ALT-PU-2020-1083
ALT-PU-2021-1587
ALT-PU-2021-2018
BDU:2023-01681
CVE-2021-27927
DLA-3390-1
OPENSUSE-SU-2022:0036-1
OPENSUSE-SU-2022_0036-1
OPENSUSE-SU-2022_0058-1
OPENSUSE-SU-2024:11539-1
SUSE-SU-2021:0990-1

Affected Products

Alt Linux
Astra Linux
Suse
Zabbix