Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-2826

Опубликовано: 09 апр. 2018
Источник: debian
EPSS Низкий

Описание

An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy request can cause the Zabbix server to send the configuration information of any Zabbix proxy, resulting in information disclosure. An attacker can make requests from an active Zabbix proxy to trigger this vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zabbixfixed1:4.0.0+dfsg-1package
zabbixignoredstretchpackage
zabbixignoredjessiepackage

Примечания

  • https://talosintelligence.com/vulnerability_reports/TALOS-2017-0327

  • Relates to the information disclosure as mentioned in (but is not the same issue)

  • https://support.zabbix.com/browse/ZBX-12076

  • Workaround for Zabbix 3.0 exists: https://www.zabbix.com/documentation/3.0/manual/distributed_monitoring/proxies#configuration

  • using encrypted connections with the proxy.

EPSS

Процентиль: 49%
0.00262
Низкий

Связанные уязвимости

CVSS3: 3.7
ubuntu
почти 8 лет назад

An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy request can cause the Zabbix server to send the configuration information of any Zabbix proxy, resulting in information disclosure. An attacker can make requests from an active Zabbix proxy to trigger this vulnerability.

CVSS3: 3.7
nvd
почти 8 лет назад

An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy request can cause the Zabbix server to send the configuration information of any Zabbix proxy, resulting in information disclosure. An attacker can make requests from an active Zabbix proxy to trigger this vulnerability.

CVSS3: 3.7
github
больше 3 лет назад

An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy request can cause the Zabbix server to send the configuration information of any Zabbix proxy, resulting in information disclosure. An attacker can make requests from an active Zabbix proxy to trigger this vulnerability.

EPSS

Процентиль: 49%
0.00262
Низкий