Cross-site scripting in Zabbix - CVE-2022-24349
Published: July 17, 2024
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in action configuration window of Zabbix Frontend. A remote user can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Fedora
SUSE Linux Enterprise Server
zabbix-agent
zabbix-agent-debuginfo
zabbix-debugsource
zabbix40
zabbix50
zabbix
How to mitigate CVE-2022-24349
zabbix-agent - update to 4.0.12-4.15.2
zabbix-agent-debuginfo - update to 4.0.12-4.15.2
zabbix-debugsource - update to 4.0.12-4.15.2
zabbix40 - addressed in versions 4.0.39-1.el7, 4.0.39-1.el8
zabbix50 - update to 5.0.21-1.el7
zabbix - addressed in versions 5.0.21-1.fc34, 5.0.21-1.fc35, 5.0.21-1.fc36, 5.0-820220312165755.9edba152
External References
- https://support.zabbix.com/browse/ZBX-20680
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2V4N22R3QVTYAJMWFK2U2O6QXAZYM35Z/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SWDZONUHDYKBXTAIAGHSYQDEGORD2QT7/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QWP6UBFA5T6MOQPY2VDUG5YAJBFPYRFF/
- https://lists.debian.org/debian-lts-announce/2022/04/msg00011.html
- https://lists.debian.org/debian-lts-announce/2023/04/msg00013.html