-
Type:
Change Request
-
Resolution: Fixed
-
Priority:
Medium
-
Affects Version/s: 6.0.43, 7.0.22, 7.4.5, 7.4.6, 8.0.0alpha1
-
Component/s: Frontend (F)
-
S26-W06/07, S26-W12/13, S26-W14/15, S26-W16/17, S26-W18/19, S26-W20/21
-
1
The current Trapper item configuration contains an insecure default value for the Allowed hosts field. According to the documentation:
List of comma-delimited IP addresses (optionally in CIDR notation) or DNS names.
If specified, incoming connections will be accepted only from the hosts listed here.
In the default configuration, without enforced encryption, anyone can push values. Proper and secure logic for the "Allow list" is "deny all unless explicitly set". Currently, it is the other way around.
- causes
-
ZBXNEXT-10594 Empty "Proxy address" field in UI proxy settings
-
- Open
-
-
ZBX-28019 PHP runtime error appears in logs when template with Zabbix trapper and Discovery is imported in master from 7.0
-
- READY TO DEVELOP
-
- part of
-
ZBX-27287 not empty "Allowed hosts" for API method "history.push" behaves strange way
-
- Closed
-