Zabbix 2.0.5 allows remote authenticated users to discover the LDAP bind password by leveraging management-console access and reading the ldap_bind_password value in the HTML source code.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://archives.neohapsis.com/archives/fulldisclosure/2013-09/0149.html | mailing list |
http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132377.html | vendor advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132376.html | vendor advisory |