CVE-2021-27927

Name
CVE-2021-27927
Description
In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0beta2, the CControllerAuthenticationUpdate controller lacks a CSRF protection mechanism. The code inside this controller calls diableSIDValidation inside the init() method. An attacker doesn't have to know Zabbix user login credentials, but has to know the correct Zabbix URL and contact information of an existing user with sufficient privileges.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Issue Tracking https://support.zabbix.com/browse/ZBX-18942

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* zabbix >= None < 4.0.28
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* zabbix >= 5.0.0 < 5.0.8
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* zabbix >= 5.1.0 < 5.2.4
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* zabbix >= 4.0.0 <= 4.0.27
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* zabbix >= 5.0.0 <= 5.0.9
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* zabbix >= 5.2.0 <= 5.2.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status