Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate application usernames based on the variability of server responses (e.g., the "Login name or password is incorrect" and "No permissions for system access" messages, or just blocking for a number of seconds). This affects both api_jsonrpc.php and index.php.
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Link | Tags |
---|---|
https://support.zabbix.com/browse/ZBX-16532 | vendor advisory |
https://lists.debian.org/debian-lts-announce/2021/04/msg00018.html | third party advisory mailing list |
https://lists.debian.org/debian-lts-announce/2023/04/msg00013.html | mailing list |