CVE-2014-1685

Zabbix <2.8.20rc2, <2.0.11rc2, <2.2.2rc1 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Frontend in Zabbix before 1.8.20rc2, 2.0.x before 2.0.11rc2, and 2.2.x before 2.2.2rc1 allows remote "Zabbix Admin" users to modify the media of arbitrary users via unspecified vectors.

References (3)

Core 3
Core References
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132377.html
Various Sources x_refsource_confirm
https://support.zabbix.com/browse/ZBX-7693
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132376.html

Scores

EPSS 0.0141
EPSS Percentile 69.9%

Details

Status published
Products (23)
fedoraproject/fedora 19
fedoraproject/fedora 20
zabbix/zabbix 1.8
zabbix/zabbix 1.8.1
zabbix/zabbix 1.8.2
zabbix/zabbix 1.8.3 rc1 (3 CPE variants)
zabbix/zabbix 1.8.15 rc1
zabbix/zabbix 1.8.16
zabbix/zabbix 1.8.18
zabbix/zabbix 2.0.0 (7 CPE variants)
... and 13 more
Published May 08, 2014
Tracked Since Feb 18, 2026