CVE-2019-17382: Critical severity zabbix server vulnerability
An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and access the dashboard page, and then create a Dashboard, Report, Screen, or Map without any Username/Password (i.e., anonymously). All created elements (Dashboard/Report/Screen/Map) are accessible by other users and by an admin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-17382?
The severity of CVE-2019-17382 is critical, with a score of 9.1.
How can an attacker exploit CVE-2019-17382?
An attacker can bypass the login page of Zabbix through 4.4 and access the dashboard page to create elements without any Username/Password.
What is the affected version of Zabbix for CVE-2019-17382?
Zabbix versions up to and including 4.4 are affected by CVE-2019-17382.
How can I fix CVE-2019-17382?
Upgrade to a fixed version of Zabbix (after 4.4) as soon as possible to mitigate the vulnerability.
Are there any references available for CVE-2019-17382?
Yes, you can find more information about CVE-2019-17382 in the Debian LTS announcement and the Exploit DB page.