Database/Control plane, storage & DevOps

Zabbix frontend: host search filters on hidden fields, turning stored IPMI and PSK secrets into a guessing oracle
Impact
Zabbix's host search accepts filters on fields it never renders, including stored IPMI passwords and TLS PSK values. A read-only user can submit a guess and learn from whether the host appears in the results whether the guess matched, which recovers the secret one guess at a time without any credential ever being displayed. The stakes are the same as any monitoring credential store in a datacenter: IPMI passwords grant console and power control on the monitored nodes, and PSK identities let an attacker impersonate or intercept agent traffic. Extraction is slower than a direct disclosure bug, which is why the score is moderate, but short or reused BMC passwords fall quickly.
Who can reach it
An authenticated Zabbix frontend user with read access to the hosts in question; the vector is rated adjacent-network, so frontend reachability is assumed to be internal.
What to do
Apply the Zabbix release that fixes ZBX-28195 and restart the frontend and server components; the record does not state the fixed version, so take it from support.zabbix.com. Because the oracle may already have been used, rotate IPMI passwords and TLS PSKs for monitored hosts if untrusted read-only accounts existed - BMC password rotation across the fleet is the real cost here, not the Zabbix upgrade. Tighten which users have host read permissions in the meantime.
References
Related entries
- Keycloak: OIDC authentication flaw - attacker reusing data from a same-realm request impersonates a userCVE-2023-0264 · KeycloakMedium
- MySQL Server: InnoDB flaw allowing a high-privileged network attacker to cause a repeatable DoSCVE-2022-21417 · MySQL ServerMedium
- MySQL Server: InnoDB flaw - a high-privileged network attacker can hang or repeatedly crash the serverCVE-2023-22084 · MySQL ServerMedium
- RabbitMQ: HTTP API enforces no request body limitCVE-2023-46118 · RabbitMQMedium
- Elasticsearch: elasticsearch-certutil --csr writes the private key to disk unencrypted despite --passCVE-2024-23444 · ElasticsearchMedium
- Linux perf/x86/amd - race between amd_pmu_enable_all, perf NMI and throttling: A race between AMD PMU enablementCVE-2022-49781 · Linux perf/x86/amd - race between amd_pmu_enable_all, perf NMI and throttlingMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.