Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hh7f-cch9-52mr

Опубликовано: 05 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this way, any user will not be able to access the Zabbix Frontend while it is being maintained and possible sensitive data will be prevented from being disclosed. An attacker can bypass this protection and access the instance using IP address not listed in the defined range.

Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this way, any user will not be able to access the Zabbix Frontend while it is being maintained and possible sensitive data will be prevented from being disclosed. An attacker can bypass this protection and access the instance using IP address not listed in the defined range.

EPSS

Процентиль: 32%
0.00125
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-20
CWE-863

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 3 лет назад

Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this way, any user will not be able to access the Zabbix Frontend while it is being maintained and possible sensitive data will be prevented from being disclosed. An attacker can bypass this protection and access the instance using IP address not listed in the defined range.

CVSS3: 5.3
nvd
около 3 лет назад

Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this way, any user will not be able to access the Zabbix Frontend while it is being maintained and possible sensitive data will be prevented from being disclosed. An attacker can bypass this protection and access the instance using IP address not listed in the defined range.

CVSS3: 5.3
debian
около 3 лет назад

Zabbix Frontend provides a feature that allows admins to maintain the ...

suse-cvrf
около 3 лет назад

Security update for zabbix

CVSS3: 9.8
fstec
больше 3 лет назад

Уязвимость универсальной системы мониторинга Zabbix, связанная с неправильной авторизацией, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 32%
0.00125
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-20
CWE-863