Bug 1146086 (CVE-2019-15132)

Summary: VUL-1: CVE-2019-15132: zabbix: with login requests, it is possible to enumerate application usernames based on the variability of server responses
Product: [openSUSE] openSUSE Distribution Reporter: Alexandros Toptsoglou <atoptsoglou>
Component: SecurityAssignee: Boris Manojlovic <boris>
Status: IN_PROGRESS --- QA Contact: Security Team bot <security-team>
Severity: Minor    
Priority: P4 - Low    
Version: Leap 15.1   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/240396/
Whiteboard:
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Alexandros Toptsoglou 2019-08-19 08:12:34 UTC
CVE-2019-15132

Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is
possible to enumerate application usernames based on the variability of server
responses (e.g., the "Login name or password is incorrect" and "No permissions
for system access" messages, or just blocking for a number of seconds). This
affects both api_jsonrpc.php and index.php.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-15132
http://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-15132.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15132
http://www.cvedetails.com/cve/CVE-2019-15132/
https://support.zabbix.com/browse/ZBX-16532
Comment 1 Boris Manojlovic 2019-08-19 10:46:53 UTC
When update/fix is provided will be updated