Bug 1568053 (CVE-2017-2826) - CVE-2017-2826 zabbix: Information Disclosure in Zabbix Server Config Proxy Request
Summary: CVE-2017-2826 zabbix: Information Disclosure in Zabbix Server Config Proxy Re...
Keywords:
Status: NEW
Alias: CVE-2017-2826
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1568054 1568055 1568056 1568127
Blocks: 1568057
TreeView+ depends on / blocked
 
Reported: 2018-04-16 16:41 UTC by Laura Pardo
Modified: 2019-09-29 14:37 UTC (History)
10 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:


Attachments (Terms of Use)

Description Laura Pardo 2018-04-16 16:41:07 UTC
A flaw was found in Zabbix server 2.4.X. A specially crafted iConfig proxy request can cause the Zabbix server to send the configuration information of any Zabbix proxy, resulting in information disclosure. An attacker can make requests from an active Zabbix proxy to trigger this vulnerability.


References:
https://talosintelligence.com/vulnerability_reports/TALOS-2017-0327

Comment 1 Laura Pardo 2018-04-16 16:41:33 UTC
Created zabbix22 tracking bugs for this issue:

Affects: epel-all [bug 1568054]


Created zabbix20 tracking bugs for this issue:

Affects: epel-all [bug 1568055]

Comment 2 Laura Pardo 2018-04-16 16:43:12 UTC
Created zabbix tracking bugs for this issue:

Affects: epel-6 [bug 1568056]


Note You need to log in before you can comment on or make changes to this bug.