Uploaded image for project: 'ZABBIX FEATURE REQUESTS'
  1. ZABBIX FEATURE REQUESTS
  2. ZBXNEXT-1085

restrict available checks on the agent side

    XMLWordPrintable

    Details

    • Team:
      Team C
    • Sprint:
      Sprint 58 (Nov 2019), Sprint 59 (Dec 2019), Sprint 60 (Jan 2020)
    • Story Points:
      2.125

      Description

      As a security measure, Zabbix agent provides a configuration parameter EnableRemoteCommands to restrict system.run[] checks.

      However, system.run[] is not the only way to compromise security through Zabbix agent. For instance, a malicious administrator can potentially query vfs.file.contents[] on a user's workstation to peek on files in the system that contain cached passwords.

      Thus, it would be nice if there would be a way to restrict availability of arbitrary checks on the agent, not just system.run[].

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              atumilovics Andrejs Tumilovics
              Reporter:
              asaveljevs Aleksandrs Saveljevs
              Votes:
              8 Vote for this issue
              Watchers:
              14 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved: