MEDIUM
The API in Zabbix before 1.8.20rc1, 2.0.x before 2.0.11rc1, and 2.2.x before 2.2.2rc1 allows remote authenticated users to spoof arbitrary users via the user name in a user.login request
Published May 8, 2014
4.0
MEDIUMCVSS 2.0
EPSS 1.57%
Description
The API in Zabbix before 1.8.20rc1, 2.0.x before 2.0.11rc1, and 2.2.x before 2.2.2rc1 allows remote authenticated users to spoof arbitrary users via the user name in a user.login request.
Affected products
No data.
OR
- ≤ 1.8.19
- 1.8
- 1.8.1
- 1.8.2
- 1.8.3
- 1.8.3
- 1.8.3
- 1.8.15
- 1.8.16
- 1.8.18
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.1
- 2.0.1
- 2.0.1
- 2.0.2
- 2.0.2
- 2.0.2
- 2.0.3
- 2.0.3
- 2.0.3
- 2.0.4
- 2.0.4
- 2.0.5
- 2.0.5
- 2.0.6
- 2.0.6
- 2.0.7
- 2.0.8
- 2.0.8
- 2.0.9
- 2.0.9
- 2.0.10
- 2.2.0
- 2.2.0
- 2.2.0
- 2.2.1
- 2.2.1
- 2.2.1
- 19
- 20
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132376.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132377.html vendor-advisoryx_refsource_FEDORA
- http://www.securityfocus.com/bid/65402 vdb-entryx_refsource_BID
- https://support.zabbix.com/browse/ZBX-7703 x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132376.html | vendor-advisoryx_refsource_FEDORA | |
| http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132377.html | vendor-advisoryx_refsource_FEDORA | |
| http://www.securityfocus.com/bid/65402 | vdb-entryx_refsource_BID | |
| https://support.zabbix.com/browse/ZBX-7703 | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 8, 2014
Updated Aug 6, 2024
Reserved Jan 28, 2014
Link CVE-2014-1682
CISA Vulnrichment
Updated n/a