Zabbix
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*
- >= 6.0.0, <= 6.0.40
- >= 7.0.0, <= 7.0.17
- >= 7.2.0, <= 7.2.11
- >= 7.4.0, <= 7.4.1
A vulnerability exists in Zabbix's handling of LDAP 'Bind password' values. Once saved, the password cannot be read; however, a Super Admin can leak it by changing the LDAP 'Host' to a malicious server. This issue is present in Zabbix versions 6.0.0 through 6.0.40, 7.0.0 through 7.0.17, 7.2.0 through 7.2.11, and 7.4.0 through 7.4.1. To address this vulnerability, the 'Bind password' value is now reset whenever the 'Host' is changed.
Exploitation of this vulnerability allows a Zabbix Super Admin to leak the LDAP 'Bind password' value.
Users can update to Zabbix versions 6.0.41, 7.0.18, 7.2.12, or 7.4.2 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.