PT-2019-5822 · Zabbix+1 · Zabbix+1

CVE-2019-17382

·

Publicado

2018-10-05

·

Atualizado

2023-10-21

CVSS v2.0

9.4

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Zabbix versions prior to 4.4
Description An issue was discovered in "zabbix.php?action=dashboard.view&dashboardid=1" that allows an attacker to bypass the login page and access the dashboard page anonymously. The attacker can then create a Dashboard, Report, Screen, or Map without any username/password. All created elements are accessible by other users and by an admin. The vulnerability is related to bypassing authorization using a user-controlled key, which can allow a remote attacker to access the dashboard page and create elements.
Recommendations For Zabbix versions prior to 4.4, consider disabling access to the "zabbix.php?action=dashboard.view&dashboardid=1" endpoint until a patch is available. Restrict access to the dashboard page to minimize the risk of exploitation. Avoid using the dashboardid parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2422
ALT-PU-2019-1862
ALT-PU-2019-3069
ALT-PU-2020-1083
ALT-PU-2020-3446
ALT-PU-2021-1587
ALT-PU-2021-2018
ALT-PU-2021-2582
ALT-PU-2021-2668
ALT-PU-2021-3617
ALT-PU-2022-1975
ALT-PU-2022-2499
ALT-PU-2023-6268
BDU:2021-03179
CVE-2019-17382
DLA-3538-1
DLA-3538-2

Produtos afetados

Alt Linux
Zabbix