-
Defect (Security)
-
Resolution: Fixed
-
Trivial
-
5.0.1
-
Sprint 68 (Sep 2020), Sprint 69 (Oct 2020), Sprint 70 (Nov 2020), Sprint 71 (Dec 2020)
-
1
Steps to reproduce:
- Add PSK encyption under Administation>General>Autoregistration, after updating, PSKĀ is hidden
- Create autoregistration action to add host
- Have Zabbix server autoregister another host with the same PSK
- Go to configuration>Hosts>Autoregistered host>Encryption - PSK is visible in plain text
At this point, Administration section is available only to Super Admins and PSK is hidden there, but Configuration section is available to Administators, where they can see PSK in plain text.
Expected:
PSK under host info should be hidden
- causes
-
ZBX-19555 `inventory_mode` not returned anymore in API call `host.get` since upgrade to 5.4
- Closed
- depends on
-
ZBXNEXT-3497 auto-registration with TLS (PSK)
- Closed
- is duplicated by
-
ZBXNEXT-6018 Secret encryption details in the frontend
- Closed