It was reported [1] that the user.login method in Zabbix would accept a 'cnf' parameter containing the configuration parameters to use for LDAP authentication, which would override the configuration stored in the database. This can be used to authenticate to Zabbix using a completely different LDAP application (e.g. authenticate to Zabbix using some other LDAP directory the attacker has credentials for). This has been corrected in upstream versions 2.1.0 r32446, 2.0.5rc1 r32444 and 1.8.16rc1 r32442. Patches are attached to the upstream bug report. [1] https://support.zabbix.com/browse/ZBX-6097
Created zabbix tracking bugs for this issue Affects: epel-6 [bug 901876] Affects: fedora-all [bug 901878]
Created zabbix20 tracking bugs for this issue Affects: epel-6 [bug 901877]