Candidate: CVE-2014-1682 PublicDate: 2014-05-08 14:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1682 https://support.zabbix.com/browse/ZBX-7703 Description: The API in Zabbix before 1.8.20rc1, 2.0.x before 2.0.11rc1, and 2.2.x before 2.2.2rc1 allows remote authenticated users to spoof arbitrary users via the user name in a user.login request. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737818 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_zabbix: upstream: https://support.zabbix.com/secure/attachment/26549/ZBX-7703-2.2.1.patch upstream_zabbix: released (2.2.2) lucid_zabbix: ignored (reached end-of-life) precise_zabbix: ignored (reached end-of-life) precise/esm_zabbix: DNE (precise was needed) quantal_zabbix: ignored (reached end-of-life) saucy_zabbix: ignored (reached end-of-life) trusty_zabbix: not-affected (1:2.2.2+dfsg-1) trusty/esm_zabbix: not-affected (1:2.2.2+dfsg-1) utopic_zabbix: not-affected (1:2.2.2+dfsg-1) vivid_zabbix: not-affected (1:2.2.2+dfsg-1) vivid/stable-phone-overlay_zabbix: DNE vivid/ubuntu-core_zabbix: DNE wily_zabbix: not-affected (1:2.2.2+dfsg-1) xenial_zabbix: not-affected (1:2.2.2+dfsg-1) yakkety_zabbix: not-affected (1:2.2.2+dfsg-1) zesty_zabbix: not-affected (1:2.2.2+dfsg-1) devel_zabbix: not-affected (1:2.2.2+dfsg-1)