CVE-2025-27231: LDAP 'Bind password' field value can be leaked by a Zabbix Super Admin
The LDAP 'Bind password' value cannot be read after saving, but a Super Admin account can leak it by changing LDAP 'Host' to a rogue LDAP server. To mitigate this, the 'Bind password' value is now reset on 'Host' change.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27231?
CVE-2025-27231 has been classified with a medium severity due to the potential leakage of sensitive information by Super Admin accounts.
How do I fix CVE-2025-27231?
To mitigate CVE-2025-27231, ensure that the 'Bind password' value is reset when changing the LDAP 'Host' to prevent unauthorized access.
Which software is affected by CVE-2025-27231?
CVE-2025-27231 specifically affects Zabbix, a popular open-source monitoring software.
Can a Super Admin exploit CVE-2025-27231?
Yes, a Super Admin account can exploit CVE-2025-27231 by changing the LDAP 'Host' to potentially access the leaked 'Bind password' value.
Is there a permanent fix available for CVE-2025-27231?
Currently, the immediate mitigation involves resetting the 'Bind password' after any change to the LDAP 'Host', and monitoring for updates from Zabbix for a permanent fix.