CVE-2021-27927
openSUSE Security Advisory - openSUSE-SU-2022:0036-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0beta2, the CControllerAuthenticationUpdate controller lacks a CSRF protection mechanism. The code inside this controller calls diableSIDValidation inside the init() method. An attacker doesn't have to know Zabbix user login credentials, but has to know the correct Zabbix URL and contact information of an existing user with sufficient privileges.
En Zabbix desde las versiones 4.0.x anteriores a 4.0.28rc1, versiones 5.0.0alpha1 anteriores a 5.0.10rc1, versiones 5.2.x anteriores a 5.2.6rc1, y versiones 5.4.0alpha1 anteriores a 5.4.0beta2, el controlador CControllerAuthenticationUpdate carece de un mecanismo de protección CSRF. El código dentro de este controlador llama a diableSIDValidation dentro del método init(). Un atacante no tiene que conocer las credenciales de inicio de sesión del usuario de Zabbix, pero tiene que conocer la URL correcta de Zabbix y la información de contacto de un usuario existente con suficientes privilegios
An update that solves three vulnerabilities and has two fixes is now available. This update for zabbix fixes the following issues. Fixed possible view of the setup pages by unauthenticated users if config file already exists. Fixed CSRF protection mechanism inside CControllerAuthenticationUpdate controller. Fixed stored XSS in the URL Widget.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-03-03 CVE Reserved
- 2021-03-03 CVE Published
- 2024-08-03 CVE Updated
- 2025-07-16 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2023/04/msg00013.html | Mailing List |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.zabbix.com/browse/ZBX-18942 | 2023-04-12 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | >= 4.0.0 <= 4.0.27 Search vendor "Zabbix" for product "Zabbix" and version " >= 4.0.0 <= 4.0.27" | - |
Affected
| ||||||
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | >= 5.0.0 <= 5.0.9 Search vendor "Zabbix" for product "Zabbix" and version " >= 5.0.0 <= 5.0.9" | - |
Affected
| ||||||
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | >= 5.2.0 <= 5.2.3 Search vendor "Zabbix" for product "Zabbix" and version " >= 5.2.0 <= 5.2.3" | - |
Affected
|