The API in Zabbix before 1.8.20rc1, 2.0.x before 2.0.11rc1, and 2.2.x before 2.2.2rc1 allows remote authenticated users to spoof arbitrary users via the user name in a user.login request.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zabbix | Zabbix | * | 1.8.19 (including) |
Zabbix | Zabbix | 1.8 (including) | 1.8 (including) |
Zabbix | Zabbix | 1.8.1 (including) | 1.8.1 (including) |
Zabbix | Zabbix | 1.8.2 (including) | 1.8.2 (including) |
Zabbix | Zabbix | 1.8.3-rc1 (including) | 1.8.3-rc1 (including) |
Zabbix | Zabbix | 1.8.3-rc2 (including) | 1.8.3-rc2 (including) |
Zabbix | Zabbix | 1.8.3-rc3 (including) | 1.8.3-rc3 (including) |
Zabbix | Zabbix | 1.8.15-rc1 (including) | 1.8.15-rc1 (including) |
Zabbix | Zabbix | 1.8.16 (including) | 1.8.16 (including) |
Zabbix | Zabbix | 1.8.18 (including) | 1.8.18 (including) |
Zabbix | Zabbix | 2.0.0 (including) | 2.0.0 (including) |
Zabbix | Zabbix | 2.0.0-rc1 (including) | 2.0.0-rc1 (including) |
Zabbix | Zabbix | 2.0.0-rc2 (including) | 2.0.0-rc2 (including) |
Zabbix | Zabbix | 2.0.0-rc3 (including) | 2.0.0-rc3 (including) |
Zabbix | Zabbix | 2.0.0-rc4 (including) | 2.0.0-rc4 (including) |
Zabbix | Zabbix | 2.0.0-rc5 (including) | 2.0.0-rc5 (including) |
Zabbix | Zabbix | 2.0.0-rc6 (including) | 2.0.0-rc6 (including) |
Zabbix | Zabbix | 2.0.1 (including) | 2.0.1 (including) |
Zabbix | Zabbix | 2.0.1-rc1 (including) | 2.0.1-rc1 (including) |
Zabbix | Zabbix | 2.0.1-rc2 (including) | 2.0.1-rc2 (including) |
Zabbix | Zabbix | 2.0.2 (including) | 2.0.2 (including) |
Zabbix | Zabbix | 2.0.2-rc1 (including) | 2.0.2-rc1 (including) |
Zabbix | Zabbix | 2.0.2-rc2 (including) | 2.0.2-rc2 (including) |
Zabbix | Zabbix | 2.0.3 (including) | 2.0.3 (including) |
Zabbix | Zabbix | 2.0.3-rc1 (including) | 2.0.3-rc1 (including) |
Zabbix | Zabbix | 2.0.3-rc2 (including) | 2.0.3-rc2 (including) |
Zabbix | Zabbix | 2.0.4 (including) | 2.0.4 (including) |
Zabbix | Zabbix | 2.0.4-rc1 (including) | 2.0.4-rc1 (including) |
Zabbix | Zabbix | 2.0.5 (including) | 2.0.5 (including) |
Zabbix | Zabbix | 2.0.5-rc1 (including) | 2.0.5-rc1 (including) |
Zabbix | Zabbix | 2.0.6 (including) | 2.0.6 (including) |
Zabbix | Zabbix | 2.0.6-rc1 (including) | 2.0.6-rc1 (including) |
Zabbix | Zabbix | 2.0.7-rc1 (including) | 2.0.7-rc1 (including) |
Zabbix | Zabbix | 2.0.8-rc1 (including) | 2.0.8-rc1 (including) |
Zabbix | Zabbix | 2.0.8-rc2 (including) | 2.0.8-rc2 (including) |
Zabbix | Zabbix | 2.0.9-rc1 (including) | 2.0.9-rc1 (including) |
Zabbix | Zabbix | 2.0.9-rc2 (including) | 2.0.9-rc2 (including) |
Zabbix | Zabbix | 2.0.10-rc1 (including) | 2.0.10-rc1 (including) |
Zabbix | Zabbix | 2.2.0 (including) | 2.2.0 (including) |
Zabbix | Zabbix | 2.2.0-rc1 (including) | 2.2.0-rc1 (including) |
Zabbix | Zabbix | 2.2.0-rc2 (including) | 2.2.0-rc2 (including) |
Zabbix | Zabbix | 2.2.1 (including) | 2.2.1 (including) |
Zabbix | Zabbix | 2.2.1-rc1 (including) | 2.2.1-rc1 (including) |
Fedora | Fedoraproject | 19 (including) | 19 (including) |
Fedora | Fedoraproject | 20 (including) | 20 (including) |
Zabbix | Ubuntu | lucid | * |
Zabbix | Ubuntu | precise | * |
Zabbix | Ubuntu | quantal | * |
Zabbix | Ubuntu | saucy | * |
Zabbix | Ubuntu | upstream | * |