Security holes: network monitoring tool Zabbix can leak passwords
Summary
In August 2024 Zabbix closed eight security holes in its network monitoring. The most serious was CVE-2024-22116, through which administrators with restricted rights could execute code in the context of the ping script. In addition, the frontend’s audit log displayed passwords in plain text.
Ideas
- Monitoring systems have access to many other systems and are therefore particularly critical.
- Even restricted admin roles can lead to a complete takeover.
- Audit logs must not contain secrets in plain text.
- Further holes concerned the JavaScript engine, the Windows agent installer and file access.
Insights
- Compromising a monitoring server often opens up the entire infrastructure.
- Logging can itself become a data leak.
Facts
- The holes were closed in 5.0.43rc1, 6.0.31rc1, 6.4.16rc1 and 7.0.0rc3.
- CVE-2024-22116 was rated critical despite requiring admin rights.
References
Critique
- The fixed versions named are release candidates; whether stable versions were available remains open.
Recommendations
- Restrict admin roles in monitoring to what is necessary and check script permissions.
- Check your tools’ logs for passwords or tokens.
Links to the original source and the Web Archive open in a new tab.