CVE-2014-1682: Fedoraproject Fedora

Medium severity, CVSS 4.0. EPSS: 1.6% chance of exploitation in the next 30 days.

The API in Zabbix before 1.8.20rc1, 2.0.x before 2.0.11rc1, and 2.2.x before 2.2.2rc1 allows remote authenticated users to spoof arbitrary users via the user name in a user.login request.

Affected products

  • Fedoraproject Fedora: version 19 only; version 20 only
  • Zabbix Zabbix: up to and including 1.8.19; version 1.8 only; version 1.8.1 only; version 1.8.2 only; version 1.8.3 only; version 1.8.15 only; …

Published 2014-05-08. Last modified 2026-06-17.