Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Debian 10: DLA-3969-1 Critical: Zabbix Credentials Exposure and CSRF

debian lts
Calendar Grey April 21, 2021
Dist Debian Esm H88
Several security flaws in Zabbix enable user enumeration and cross-site scripting (XSS) vulnerabilities. Update to address these severe security concerns.
Multiple vulnerabilities were discovered in Zabbix, a network monitoring solution

Summary

Multiple vulnerabilities were discovered in Zabbix, a network
monitoring solution. An attacker may enumerate valid users and
redirect to external links through the zabbix web frontend.

CVE-2019-15132

Zabbix allows User Enumeration. With login requests, it is
possible to enumerate application usernames based on the
variability of server responses (e.g., the "Login name or password
is incorrect" and "No permissions for system access" messages, or
just blocking for a number of seconds). This affects both
api_jsonrpc.php and index.php.

CVE-2020-15803

Zabbix allows stored XSS in the URL Widget. This fix was
mistakenly dropped in previous upload 1:3.0.31+dfsg-0+deb9u1.

This update also includes several other bug fixes and
improvements. For more information please refer to the upstream
changelog file.

For Debian 9 stretch, these problems have been fixed in version
1:3.0.32+dfsg-0+deb9u1.

We recommend that you upgrade your zabbix packages.

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: zabbix
Version: 1:3.0.32+dfsg-0+deb9u1
CVE ID: CVE-2019-15132 CVE-2020-15803
Debian Bug: 935027 966146

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here