CVE-2017-2826: Infoleak
An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy request can cause the Zabbix server to send the configuration information of any Zabbix proxy, resulting in information disclosure. An attacker can make requests from an active Zabbix proxy to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-2826?
CVE-2017-2826 is an information disclosure vulnerability in the iConfig proxy request of Zabbix server 2.4.X.
What is the severity of CVE-2017-2826?
The severity of CVE-2017-2826 is medium.
How can an attacker exploit CVE-2017-2826?
An attacker can exploit CVE-2017-2826 by sending a specially crafted iConfig proxy request to the Zabbix server, causing it to disclose the configuration information of any Zabbix proxy.
Which versions of Zabbix server are affected by CVE-2017-2826?
Zabbix server versions 2.4.0 to 2.4.9, including release candidates, are affected by CVE-2017-2826.
How can I fix CVE-2017-2826?
To fix CVE-2017-2826, upgrade to a version of Zabbix server that is not affected by the vulnerability.