bk99.de entertain the web since 1997

Security holes: network monitoring tool Zabbix can leak passwords

Summary

In August 2024 Zabbix closed eight security holes in its network monitoring. The most serious was CVE-2024-22116, through which administrators with restricted rights could execute code in the context of the ping script. In addition, the frontend’s audit log displayed passwords in plain text.

Ideas

  • Monitoring systems have access to many other systems and are therefore particularly critical.
  • Even restricted admin roles can lead to a complete takeover.
  • Audit logs must not contain secrets in plain text.
  • Further holes concerned the JavaScript engine, the Windows agent installer and file access.

Insights

  • Compromising a monitoring server often opens up the entire infrastructure.
  • Logging can itself become a data leak.

Facts

  • The holes were closed in 5.0.43rc1, 6.0.31rc1, 6.4.16rc1 and 7.0.0rc3.
  • CVE-2024-22116 was rated critical despite requiring admin rights.

References

Critique

  • The fixed versions named are release candidates; whether stable versions were available remains open.

Recommendations

  • Restrict admin roles in monitoring to what is necessary and check script permissions.
  • Check your tools’ logs for passwords or tokens.

Read the original article

Search the Web Archive