CVE-2021-27927: CSRF
In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0beta2, the CControllerAuthenticationUpdate controller lacks a CSRF protection mechanism. The code inside this controller calls diableSIDValidation inside the init() method. An attacker doesn't have to know Zabbix user login credentials, but has to know the correct Zabbix URL and contact information of an existing user with sufficient privileges.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27927?
The severity of CVE-2021-27927 is high.
How can I fix CVE-2021-27927?
To fix CVE-2021-27927, you should upgrade your Zabbix installation to version 4.0.28rc1, 5.0.10rc1, 5.2.6rc1, or 5.4.0beta2.
What is the affected software for CVE-2021-27927?
The affected software for CVE-2021-27927 is Zabbix versions 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0beta2.
Does CVE-2021-27927 have a CSRF protection mechanism?
No, CVE-2021-27927 does not have a CSRF protection mechanism.
Where can I find more information about CVE-2021-27927?
You can find more information about CVE-2021-27927 in the Debian LTS announcement and the Zabbix support website.