Improper access control in Zabbix - CVE-2022-23134
Published: February 23, 2022
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions to certain steps of setup.php file. A remote non-authenticated attacker can bypass implemented security restrictions and change the configuration of Zabbix Frontend.
Affected software
Fedora
zabbix40
zabbix50
zabbix
How to mitigate CVE-2022-23134
zabbix40 - update to 4.0.37-1.el7
zabbix50 - update to 5.0.19-1.el7
zabbix - addressed in versions 5.0.19-1.fc34, 5.0.19-1.fc35, 5.0-820220117005358.9edba152
External References
- https://support.zabbix.com/browse/ZBX-20384
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6SZYHXINBKCY42ITFSNCYE7KCSF33VRA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VB6W556GVXOKUYTASTDGL3AI7S3SJHX7/
- https://lists.debian.org/debian-lts-announce/2022/02/msg00008.html