Incorrect authorization in Zabbix - CVE-2022-43515
Published: December 27, 2022
Vulnerability identifier: #VU70507
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-43515
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authorization process.
The vulnerability exists due to Zabbix Frontend relies on the X-Forwarded-For header during software maintenance. A remote attacker can use the X-Forwarded-For header to bypass implemented protection and gain access to the application frontend.
Affected software
Zabbix
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
zabbix-agent
zabbix-agent-debuginfo
zabbix-debugsource
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
zabbix-agent
zabbix-agent-debuginfo
zabbix-debugsource
How to mitigate CVE-2022-43515
Install updates from vendor's website.
Zabbix - addressed in versions 5.0.30 rc1, 6.0.11 rc1, 6.2.5 rc1
zabbix-agent - update to 4.0.12-4.21.1
zabbix-agent-debuginfo - update to 4.0.12-4.21.1
zabbix-debugsource - update to 4.0.12-4.21.1
zabbix-agent - update to 4.0.12-4.21.1
zabbix-agent-debuginfo - update to 4.0.12-4.21.1
zabbix-debugsource - update to 4.0.12-4.21.1