Per a request from the security team:
Using native functionality of the Zabbix web UI as an administrative user, it was possible to execute arbitrary commands on the Zabbix Server as the 'zabbix' user account. From here, it was possible to gain a remote shell on the Zabbix Server...
They are requesting that this be disabled. I have been searching the docs but haven't found anything (yet) that will tell how to disable (assuming it is an option).
Is it possible to disable this ability? If so, what needs to be updated?
Using native functionality of the Zabbix web UI as an administrative user, it was possible to execute arbitrary commands on the Zabbix Server as the 'zabbix' user account. From here, it was possible to gain a remote shell on the Zabbix Server...
They are requesting that this be disabled. I have been searching the docs but haven't found anything (yet) that will tell how to disable (assuming it is an option).
Is it possible to disable this ability? If so, what needs to be updated?
Comment