CVE-2014-1685
published 2014-05-08CVE-2014-1685: The Frontend in Zabbix before 1.8.20rc2, 2.0.x before 2.0.11rc2, and 2.2.x before 2.2.2rc1 allows remote "Zabbix Admin" users to modify the media of arbitrary…
PriorityP427medium5.5CVSS 2.0
AVNACLAuSCNIPAP
EPSS
1.42%
70.0th percentile
The Frontend in Zabbix before 1.8.20rc2, 2.0.x before 2.0.11rc2, and 2.2.x before 2.2.2rc1 allows remote "Zabbix Admin" users to modify the media of arbitrary users via unspecified vectors.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zabbix | < zabbix 1:2.2.2+dfsg-1 (bookworm) | zabbix 1:2.2.2+dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| zabbix | zabbix | <= 1.8.19 | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | >= 0 < 1:2.2.2+dfsg-1 | 1:2.2.2+dfsg-1 |
CVSS provenance
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8jhf-8qjr-8c39: The Frontend in Zabbix before 1
ghsa_unreviewed·2022-05-17
CVE-2014-1685 [MEDIUM] GHSA-8jhf-8qjr-8c39: The Frontend in Zabbix before 1
The Frontend in Zabbix before 1.8.20rc2, 2.0.x before 2.0.11rc2, and 2.2.x before 2.2.2rc1 allows remote "Zabbix Admin" users to modify the media of arbitrary users via unspecified vectors.
OSV
CVE-2014-1685: The Frontend in Zabbix before 1
osv·2014-05-08·CVSS 5.5
CVE-2014-1685 [MEDIUM] CVE-2014-1685: The Frontend in Zabbix before 1
The Frontend in Zabbix before 1.8.20rc2, 2.0.x before 2.0.11rc2, and 2.2.x before 2.2.2rc1 allows remote "Zabbix Admin" users to modify the media of arbitrary users via unspecified vectors.
Debian
CVE-2014-1685: zabbix - The Frontend in Zabbix before 1.8.20rc2, 2.0.x before 2.0.11rc2, and 2.2.x befor...
vendor_debian·2014·CVSS 5.5
CVE-2014-1685 [MEDIUM] CVE-2014-1685: zabbix - The Frontend in Zabbix before 1.8.20rc2, 2.0.x before 2.0.11rc2, and 2.2.x befor...
The Frontend in Zabbix before 1.8.20rc2, 2.0.x before 2.0.11rc2, and 2.2.x before 2.2.2rc1 allows remote "Zabbix Admin" users to modify the media of arbitrary users via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 1:2.2.2+dfsg-1)
bullseye: resolved (fixed in 1:2.2.2+dfsg-1)
forky: resolved (fixed in 1:2.2.2+dfsg-1)
sid: resolved (fixed in 1:2.2.2+dfsg-1)
trixie: resolved (fixed in 1:2.2.2+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-1685 zabbix22: zabbix: unauthorized modification of user media via Zabbix Admin users [epel-6]
bugzilla·2014-05-08·CVSS 5.5
CVE-2014-1685 [MEDIUM] CVE-2014-1685 zabbix22: zabbix: unauthorized modification of user media via Zabbix Admin users [epel-6]
CVE-2014-1685 zabbix22: zabbix: unauthorized modification of user media via Zabbix Admin users [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epe
Bugzilla
CVE-2014-1685 zabbix: unauthorized modification of user media via Zabbix Admin users
bugzilla·2014-05-08·CVSS 5.5
CVE-2014-1685 [MEDIUM] CVE-2014-1685 zabbix: unauthorized modification of user media via Zabbix Admin users
CVE-2014-1685 zabbix: unauthorized modification of user media via Zabbix Admin users
Common Vulnerabilities and Exposures assigned an identifier CVE-2014-1685 to
the following vulnerability:
Name: CVE-2014-1685
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1685
Assigned: 20140128
Reference: https://support.zabbix.com/browse/ZBX-7693
Reference: FEDORA:FEDORA-2014-5540
Reference: http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132377.html
Reference: FEDORA:FEDORA-2014-5551
Reference: http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132376.html
The Frontend in Zabbix before 1.8.20rc2, 2.0.x before 2.0.11rc2, and
2.2.x before 2.2.2rc1 allows remote "Zabbix Admin" users to modify the
media of arbitrary users via unspecified vectors.
Curren
http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132376.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-May/132377.htmlhttps://support.zabbix.com/browse/ZBX-7693http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132376.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-May/132377.htmlhttps://support.zabbix.com/browse/ZBX-7693
2014-05-08
Published