CVE-2014-1682
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
08/05/2014
Last modified:
12/04/2025
Description
The API in Zabbix before 1.8.20rc1, 2.0.x before 2.0.11rc1, and 2.2.x before 2.2.2rc1 allows remote authenticated users to spoof arbitrary users via the user name in a user.login request.
Impact
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* | 1.8.19 (including) | |
| cpe:2.3:a:zabbix:zabbix:1.8:*:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:1.8.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:1.8.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:1.8.3:rc1:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:1.8.3:rc2:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:1.8.3:rc3:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:1.8.15:rc1:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:1.8.16:*:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:1.8.18:*:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:2.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:2.0.0:rc1:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:2.0.0:rc2:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:2.0.0:rc3:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:2.0.0:rc4:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132376.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132377.html
- http://www.securityfocus.com/bid/65402
- https://support.zabbix.com/browse/ZBX-7703
- http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132376.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132377.html
- http://www.securityfocus.com/bid/65402
- https://support.zabbix.com/browse/ZBX-7703



