Bug 1146086 - (CVE-2019-15132) VUL-1: CVE-2019-15132: zabbix: with login requests, it is possible to enumerate application usernames based on the variability of server responses
(CVE-2019-15132)
VUL-1: CVE-2019-15132: zabbix: with login requests, it is possible to enumera...
Status: IN_PROGRESS
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.1
Other Other
: P4 - Low : Minor (vote)
: ---
Assigned To: Boris Manojlovic
Security Team bot
https://smash.suse.de/issue/240396/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-08-19 08:12 UTC by Alexandros Toptsoglou
Modified: 2019-08-19 22:13 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexandros Toptsoglou 2019-08-19 08:12:34 UTC
CVE-2019-15132

Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is
possible to enumerate application usernames based on the variability of server
responses (e.g., the "Login name or password is incorrect" and "No permissions
for system access" messages, or just blocking for a number of seconds). This
affects both api_jsonrpc.php and index.php.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-15132
http://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-15132.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15132
http://www.cvedetails.com/cve/CVE-2019-15132/
https://support.zabbix.com/browse/ZBX-16532
Comment 1 Boris Manojlovic 2019-08-19 10:46:53 UTC
When update/fix is provided will be updated