The LDAP Bind password value cannot be read after saving, but a Super Admin account can leak it by changing LDAP Host to a rogue LDAP server. To mitigate this, the Bind password value is now reset on Host change.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zabbix | Zabbix | 6.0.0 (including) | 6.0.41 (excluding) |
Zabbix | Zabbix | 7.0.0 (including) | 7.0.18 (excluding) |
Zabbix | Zabbix | 7.2.0 (including) | 7.2.12 (excluding) |
Zabbix | Zabbix | 7.4.0 (including) | 7.4.2 (excluding) |