CVE-2021-27927
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0beta2, the CControllerAuthenticationUpdate controller lacks a CSRF protection mechanism. The code inside this controller calls diableSIDValidation inside the init() method. An attacker doesn't have to know Zabbix user login credentials, but has to know the correct Zabbix URL and contact information of an existing user with sufficient privileges.
En Zabbix desde las versiones 4.0.x anteriores a 4.0.28rc1, versiones 5.0.0alpha1 anteriores a 5.0.10rc1, versiones 5.2.x anteriores a 5.2.6rc1, y versiones 5.4.0alpha1 anteriores a 5.4.0beta2, el controlador CControllerAuthenticationUpdate carece de un mecanismo de protección CSRF. El código dentro de este controlador llama a diableSIDValidation dentro del método init(). Un atacante no tiene que conocer las credenciales de inicio de sesión del usuario de Zabbix, pero tiene que conocer la URL correcta de Zabbix y la información de contacto de un usuario existente con suficientes privilegios
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-03-03 CVE Reserved
- 2021-03-03 CVE Published
- 2023-11-17 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2023/04/msg00013.html | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.zabbix.com/browse/ZBX-18942 | 2023-04-12 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | >= 4.0.0 <= 4.0.27 Search vendor "Zabbix" for product "Zabbix" and version " >= 4.0.0 <= 4.0.27" | - |
Affected
| ||||||
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | >= 5.0.0 <= 5.0.9 Search vendor "Zabbix" for product "Zabbix" and version " >= 5.0.0 <= 5.0.9" | - |
Affected
| ||||||
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | >= 5.2.0 <= 5.2.3 Search vendor "Zabbix" for product "Zabbix" and version " >= 5.2.0 <= 5.2.3" | - |
Affected
|