CVE-2025-27231 - LDAP 'Bind password' field value can be leaked by a Zabbix Super Admin
CVE ID : CVE-2025-27231
Published : Oct. 3, 2025, 11:25 a.m. | 34 minutes ago
Description : The LDAP 'Bind password' value cannot be read after saving, but a Super Admin account can leak it by changing LDAP 'Host' to a rogue LDAP server. To mitigate this, the 'Bind password' value is now reset on 'Host' change.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 3, 2025, 11:25 a.m. | 34 minutes ago
Description : The LDAP 'Bind password' value cannot be read after saving, but a Super Admin account can leak it by changing LDAP 'Host' to a rogue LDAP server. To mitigate this, the 'Bind password' value is now reset on 'Host' change.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...