[ZBX-15093] PSK Key should not be available to base User in API call Created: 2018 Oct 24  Updated: 2024 Apr 10  Resolved: 2018 Oct 30

Status: Closed
Project: ZABBIX BUGS AND ISSUES
Component/s: API (A), Proxy (P)
Affects Version/s: 3.0.22, 4.0.2rc1
Fix Version/s: None

Type: Incident report Priority: Critical
Reporter: Nick Miethe Assignee: Zabbix Development Team
Resolution: Duplicate Votes: 0
Labels: None
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified

Issue Links:
Sub-task
part of ZBXNEXT-2461 Password and passphrase should not be... Closed
Team: Team B
Team: Team B
Sprint: Sprint 45, Sprint 46, Nov 2018
Story Points: 0

 Description   

Steps to reproduce:

  1. An API call with a user of any level (user, admin, superadmin) of proxy.get will return the PSK key.

Encryption information should not be visible to user type User in API calls.


Generated at Fri Apr 19 13:38:49 EEST 2024 using Jira 9.12.4#9120004-sha1:625303b708afdb767e17cb2838290c41888e9ff0.