Zabbix stores user passwords as MD5 hashes

XMLWordPrintable

    • Type: Incident report
    • Resolution: Duplicate
    • Priority: Minor
    • None
    • Affects Version/s: 4.4.0alpha2
    • Component/s: API (A)
    • None

      Zabbix before version 4.4.0alpha2 stores credentials in the "users" table with the password hash stored as a MD5 hash, which is a known insecure hashing method. Furthermore, no salt is used with the hash.

            Assignee:
            Oleksii Zagorskyi
            Reporter:
            itsecurityco
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: