[ZBX-13458] Inaccessible Hostname reveals to non-super-admin on maps link Created: 2018 Feb 09  Updated: 2018 Mar 12  Resolved: 2018 Mar 12

Status: Closed
Project: ZABBIX BUGS AND ISSUES
Component/s: Frontend (F)
Affects Version/s: None
Fix Version/s: 3.4.8rc1, 4.0.0alpha5, 4.0 (plan)

Type: Problem report Priority: Trivial
Reporter: Larisa Grigorjeva Assignee: Alexander Vladishev
Resolution: Fixed Votes: 0
Labels: label, link, macros, map, privacy
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified

Attachments: PNG File Selection_244.png     PNG File Selection_245.png     PNG File Selection_246.png    
Issue Links:
Sub-task
depends on ZBX-13494 Macros in labels of link elements in ... Closed
Team: Team B
Sprint: Sprint 29
Story Points: 0.125

 Description   

If Admin is using macros on link label

 {host:key.func(param)} 

on inaccessible trigger, simple user can see restricted hostname on this label.
For example this expression was used:

 {7H:proc.num[].last()} 

For admin map looks like this:

And how it looks like for simple user:

Host 7H is not accessible to user in any way, but as its name is written in unresolved label macros and as this trigger is also inaccessible for user, it is shown in macros expression.



 Comments   
Comment by Alexander Vladishev [ 2018 Mar 05 ]

Will be fixed with ZBX-13494.

Comment by Alexander Vladishev [ 2018 Mar 05 ]

Fixed in dev branch svn://svn.zabbix.com/branches/dev/ZBX-13494 .

Comment by Alexander Vladishev [ 2018 Mar 12 ]

Fixed in 3.4.8rc1 r78574 and 4.0.0alpha5 r78575.

Generated at Thu Mar 28 22:52:21 EET 2024 using Jira 9.12.4#9120004-sha1:625303b708afdb767e17cb2838290c41888e9ff0.