CVE Vulnerabilities

CVE-2013-1364

Improper Authentication

Published: Dec 14, 2013 | Modified: Dec 16, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows remote attackers to override LDAP configuration via the cnf parameter.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Zabbix Zabbix * 1.8.15 (including)
Zabbix Zabbix 2.0.0 (including) 2.0.0 (including)
Zabbix Zabbix 2.0.1 (including) 2.0.1 (including)
Zabbix Zabbix 2.0.2 (including) 2.0.2 (including)
Zabbix Zabbix 2.0.3 (including) 2.0.3 (including)
Zabbix Zabbix 2.0.4 (including) 2.0.4 (including)

Potential Mitigations

References