CVE-2014-1682 Information
Feb 14, 2021
cve
Description
The API in Zabbix before 1.8.20rc1 2.0.x before 2.0.11rc1 and 2.2.x before 2.2.2rc1 allows remote authenticated users to spoof arbitrary users via the user name in a user.login request.
Reference
http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132376.html http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132377.html http://www.securityfocus.com/bid/65402 https://support.zabbix.com/browse/ZBX-7703
Share on: