Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-23134

Опубликовано: 13 янв. 2022
Источник: debian
EPSS Критический

Описание

After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zabbixfixed1:6.0.7+dfsg-2package
zabbixnot-affectedbullseyepackage
zabbixnot-affectedbusterpackage

Примечания

  • https://support.zabbix.com/browse/ZBX-20384

  • https://git.zabbix.com/projects/ZBX/repos/zabbix/commits/aa0fecfbcc9794bc00206630a7424575dfc944df (5.0.19rc2)

  • 4.0 and 5.0 are not affected: https://support.zabbix.com/browse/ZBX-20384?focusedCommentId=648239&page=com.atlassian.jira.plugin.system.issuetabpanels%3Acomment-tabpanel#comment-648239

EPSS

Процентиль: 100%
0.93096
Критический

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 4 лет назад

After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

CVSS3: 3.7
nvd
около 4 лет назад

After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

CVSS3: 5.3
github
почти 4 года назад

After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

CVSS3: 5.3
fstec
около 4 лет назад

Уязвимость конфигурации setup.php универсальной системы мониторинга Zabbix , связанная с ошибками авторизации, позволяющая нарушителю изменить параметры конфигурации

suse-cvrf
почти 4 года назад

Security update for zabbix

EPSS

Процентиль: 100%
0.93096
Критический