Ad Widget

Collapse

How to report security vulnerabilities

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • dogasantos
    Junior Member
    • Jan 2015
    • 3

    #1

    How to report security vulnerabilities

    Hi,
    i'm searching here and along zabbix website without luck.
    Anyone knows how do I have to proceed to report security vulnerabilities on zabbix?

    Thanks.
  • coreychristian
    Senior Member
    Zabbix Certified Specialist
    • Jun 2012
    • 159

    #2
    To my knowledge there isn't a really good way to do this with zabbix and specific scanning tools tend to be a better way to go.

    Granted you could likely have zabbix monitor the results of those scanning tools, but since vulnerabilities change month to month (sometimes more frequently) You would have to create a template and keep the items/triggers updated that are looking for specific vulnerabilities.

    If there is a better option with zabbix would love to hear it though.

    Comment

    • dogasantos
      Junior Member
      • Jan 2015
      • 3

      #3
      Originally posted by coreychristian
      To my knowledge there isn't a really good way to do this with zabbix and specific scanning tools tend to be a better way to go.

      Granted you could likely have zabbix monitor the results of those scanning tools, but since vulnerabilities change month to month (sometimes more frequently) You would have to create a template and keep the items/triggers updated that are looking for specific vulnerabilities.

      If there is a better option with zabbix would love to hear it though.
      Sorry, i think I was not clear on my previous post.

      I found a security vulnerability on zabbix source code, so I want to report zabbix devel team to fix that. But i can't find informations to how to do this. Just post it here it's not a good idea, i think.

      Comment

      • tchjts1
        Senior Member
        • May 2008
        • 1605

        #4
        I will have a Zabbix staff member contact you.

        Comment

        • coreychristian
          Senior Member
          Zabbix Certified Specialist
          • Jun 2012
          • 159

          #5
          Originally posted by dogasantos
          Sorry, i think I was not clear on my previous post.

          I found a security vulnerability on zabbix source code, so I want to report zabbix devel team to fix that. But i can't find informations to how to do this. Just post it here it's not a good idea, i think.
          Probably my lack of caffiene as well

          If you have access, I believe you can report bugs and other software issues at the following link, not sure if you need a support contract though.



          Or wait for the staff member to reach out to you

          Comment

          • richlv
            Senior Member
            Zabbix Certified Trainer
            Zabbix Certified SpecialistZabbix Certified Professional
            • Oct 2005
            • 3112

            #6
            Originally posted by dogasantos
            Sorry, i think I was not clear on my previous post.

            I found a security vulnerability on zabbix source code, so I want to report zabbix devel team to fix that. But i can't find informations to how to do this. Just post it here it's not a good idea, i think.
            depending on how critical it is, you may choose to either report it in the public bugtracker (if it's minor) or send information in an encrypted email (if it's serious).

            in the latter case, please send the details to [email protected] - you may find the public gpg key in the sks keyservers (see https://sks-keyservers.net/)

            thank you for your interest in zabbix and looking forward to receiving the information on the security problem.
            Zabbix 3.0 Network Monitoring book

            Comment

            • dogasantos
              Junior Member
              • Jan 2015
              • 3

              #7
              Originally posted by richlv
              depending on how critical it is, you may choose to either report it in the public bugtracker (if it's minor) or send information in an encrypted email (if it's serious).

              in the latter case, please send the details to [email protected] - you may find the public gpg key in the sks keyservers (see https://sks-keyservers.net/)

              thank you for your interest in zabbix and looking forward to receiving the information on the security problem.
              Nice!
              Thanks @coreychristian, @richlv, @tchjts1.
              I'll use the bugtracker, it's a low risk vulnerability.
              But i'll keep these contacts in mind!!!

              Comment

              • garry3800
                Junior Member
                • May 2019
                • 4

                #8
                Dear Sir:
                we find a vulnerability by Acunetix,
                Login page password-guessing attack(CWE-307) in /zabbix/index.php
                will zabbix fix it?
                Attached Files

                Comment

                • garry3800
                  Junior Member
                  • May 2019
                  • 4

                  #9
                  Dear Sir:
                  We find a vulnerability by Acunetix,zabbix version is 4.2.
                  Vulnerable Javascript library(CWE-16) in /jsLoader.php
                  will zabbix fix it?
                  Attached Files

                  Comment

                • vmurzins
                  Zabbix developer
                  • Feb 2017
                  • 1

                  #10
                  Hello garry3800,

                  Thank you for sharing your security vulnerability findings with us.

                  About jQuery vulnerability: as Atsushi mentioned, we recently investigated it. None of currently known jQuery vulnerabilities can be used to compromise Zabbix security. See: https://support.zabbix.com/browse/ZBX-16069.
                  About password-guessing attack: We are blocking login attempts upon multiple incorrect password entries. As such, more information about the problem would be needed to understand the problem, you are mentioning. Can you, please, send it to [email protected].

                  Thank you.

                  Comment

                  • garry3800
                    Junior Member
                    • May 2019
                    • 4

                    #11
                    Dear Sir:
                    We find a vulnerability,medium issue by Webinspect,zabbix version is 4.4.
                    Path Manipulation: Relative Path Overwrite ( 11392 ) View Description
                    CWE: 79
                    Kingdom: API Abuse
                    will zabbix fix it?
                    Attached Files

                    Comment

                    • garry3800
                      Junior Member
                      • May 2019
                      • 4

                      #12
                      Dear Sir:
                      We find a vulnerability,High issue by Webinspect,zabbix version is 4.4.
                      Often Misused: File Upload ( 11503 )
                      CWE: 434
                      Kingdom: API Abuse
                      will zabbix fix it?
                      Attached Files

                      Comment

                      Working...