An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy request can cause the Zabbix server to send the configuration information of any Zabbix proxy, resulting in information disclosure. An attacker can make requests from an active Zabbix proxy to trigger this vulnerability.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1708-1 | zabbix security update |
EUVD |
EUVD-2017-11967 | An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy request can cause the Zabbix server to send the configuration information of any Zabbix proxy, resulting in information disclosure. An attacker can make requests from an active Zabbix proxy to trigger this vulnerability. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2024-09-17T00:15:28.741Z
Reserved: 2016-12-01T00:00:00
Link: CVE-2017-2826
No data.
Status : Modified
Published: 2018-04-09T20:29:00.217
Modified: 2024-11-21T03:24:13.680
Link: CVE-2017-2826
No data.
OpenCVE Enrichment
No data.
Debian DLA
EUVD