zabbix: LDAP authentication override
| Package(s): | zabbix | CVE #(s): | CVE-2013-1364 | ||||||||||||
| Created: | January 28, 2013 | Updated: | January 30, 2013 | ||||||||||||
| Description: | From the Red Hat bugzilla:
It was reported that the user.login method in Zabbix would accept a 'cnf' parameter containing the configuration parameters to use for LDAP authentication, which would override the configuration stored in the database. This can be used to authenticate to Zabbix using a completely different LDAP application (e.g. authenticate to Zabbix using some other LDAP directory the attacker has credentials for). This has been corrected in upstream versions 2.1.0 r32446, 2.0.5rc1 r32444 and 1.8.16rc1 r32442. | ||||||||||||||
| Alerts: |
| ||||||||||||||
