5.3

CVE-2022-23134

Warnung

Possible view of the setup pages by unauthenticated users if config file already exists

After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zabbix ≫ Zabbix Version >= 5.4.0 <= 5.4.8
Zabbix ≫ Zabbix Version 6.0.0 Update alpha1
Zabbix ≫ Zabbix Version 6.0.0 Update alpha2
Zabbix ≫ Zabbix Version 6.0.0 Update alpha3
Zabbix ≫ Zabbix Version 6.0.0 Update alpha4
Zabbix ≫ Zabbix Version 6.0.0 Update alpha5
Zabbix ≫ Zabbix Version 6.0.0 Update alpha6
Zabbix ≫ Zabbix Version 6.0.0 Update alpha7
Zabbix ≫ Zabbix Version 6.0.0 Update beta1
Fedoraproject ≫ Fedora Version 34
Fedoraproject ≫ Fedora Version 35
Debian ≫ Debian Linux Version 9.0

22.02.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Zabbix Frontend Improper Access Control Vulnerability

Schwachstelle

Malicious actors can pass step checks and potentially change the configuration of Zabbix Frontend.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 84.66% 0.997
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
security@zabbix.com 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6SZYHXINBKCY42ITFSNCYE7KCSF33VRA/
Release Notes
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VB6W556GVXOKUYTASTDGL3AI7S3SJHX7/
Release Notes
https://lists.debian.org/debian-lts-announce/2022/02/msg00008.html
Third Party Advisory
Mailing List
https://support.zabbix.com/browse/ZBX-20384
Patch
Vendor Advisory
Issue Tracking
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-23134
US Government Resource