Uploaded image for project: 'ZABBIX BUGS AND ISSUES'
  1. ZABBIX BUGS AND ISSUES
  2. ZBX-15093

PSK Key should not be available to base User in API call

    Details

    • Type: Incident report
    • Status: Closed
    • Priority: Critical
    • Resolution: Duplicate
    • Affects Version/s: 3.0.22, 4.0.2rc1
    • Fix Version/s: None
    • Component/s: API (A), Proxy (P)
    • Labels:
      None
    • Team:
      Team B
    • Sprint:
      Sprint 45, Sprint 46, Nov 2018
    • Story Points:
      0

      Description

      Steps to reproduce:

      1. An API call with a user of any level (user, admin, superadmin) of proxy.get will return the PSK key.

      Encryption information should not be visible to user type User in API calls.

        Attachments

          Issue Links

            Activity

              People

              • Assignee:
                zabbix.dev Zabbix Development Team
                Reporter:
                nick.miethe Nick Miethe
              • Votes:
                0 Vote for this issue
                Watchers:
                4 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved: