Описание
The API in Zabbix before 1.8.20rc1, 2.0.x before 2.0.11rc1, and 2.2.x before 2.2.2rc1 allows remote authenticated users to spoof arbitrary users via the user name in a user.login request.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 1:2.2.2+dfsg-1 |
| esm-apps/xenial | not-affected | 1:2.2.2+dfsg-1 |
| esm-infra-legacy/trusty | not-affected | 1:2.2.2+dfsg-1 |
| lucid | ignored | end of life |
| precise | ignored | end of life |
| precise/esm | DNE | precise was needed |
| quantal | ignored | end of life |
| saucy | ignored | end of life |
| trusty | not-affected | 1:2.2.2+dfsg-1 |
| trusty/esm | not-affected | 1:2.2.2+dfsg-1 |
Показывать по
EPSS
4 Medium
CVSS2
Связанные уязвимости
The API in Zabbix before 1.8.20rc1, 2.0.x before 2.0.11rc1, and 2.2.x before 2.2.2rc1 allows remote authenticated users to spoof arbitrary users via the user name in a user.login request.
The API in Zabbix before 1.8.20rc1, 2.0.x before 2.0.11rc1, and 2.2.x ...
The API in Zabbix before 1.8.20rc1, 2.0.x before 2.0.11rc1, and 2.2.x before 2.2.2rc1 allows remote authenticated users to spoof arbitrary users via the user name in a user.login request.
EPSS
4 Medium
CVSS2