Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8rh3-5c87-wh48

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate application usernames based on the variability of server responses (e.g., the "Login name or password is incorrect" and "No permissions for system access" messages, or just blocking for a number of seconds). This affects both api_jsonrpc.php and index.php.

Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate application usernames based on the variability of server responses (e.g., the "Login name or password is incorrect" and "No permissions for system access" messages, or just blocking for a number of seconds). This affects both api_jsonrpc.php and index.php.

EPSS

Процентиль: 61%
0.00412
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-203

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 6 лет назад

Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate application usernames based on the variability of server responses (e.g., the "Login name or password is incorrect" and "No permissions for system access" messages, or just blocking for a number of seconds). This affects both api_jsonrpc.php and index.php.

CVSS3: 5.3
nvd
больше 6 лет назад

Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate application usernames based on the variability of server responses (e.g., the "Login name or password is incorrect" and "No permissions for system access" messages, or just blocking for a number of seconds). This affects both api_jsonrpc.php and index.php.

CVSS3: 5.3
debian
больше 6 лет назад

Zabbix through 4.4.0alpha1 allows User Enumeration. With login request ...

CVSS3: 5.3
fstec
больше 6 лет назад

Уязвимость реализации сценариев api_jsonrpc.php и index.php универсальной системы мониторинга Zabbix, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 61%
0.00412
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-203