Uploaded image for project: 'ZABBIX BUGS AND ISSUES'
  1. ZABBIX BUGS AND ISSUES
  2. ZBX-5287

Users receive GUI messages for events on hosts that they don't have permissions to view.

    XMLWordPrintable

    Details

    • Type: Incident report
    • Status: Closed
    • Priority: Minor
    • Resolution: Cannot Reproduce
    • Affects Version/s: 1.8.12
    • Fix Version/s: None
    • Component/s: Frontend (F)
    • Labels:
      None

      Description

      The javacript rpc handler (jsrpc.php) does not check user permissions when replying to hosts. The result is that users receive alerts for hosts that they do not have permission to view.

      This can be troublesome in environments where multiple departments are using a single Zabbix instance.

      I have created and tested a patch for this issue for version 1.8.12, but presumably it should work for other versions as well.

        Attachments

          Activity

            People

            Assignee:
            Unassigned Unassigned
            Reporter:
            wcs1only Charlie Stanley
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved: