CVE-2022-23134: Possible view of the setup pages by unauthenticated users if config file already exists
After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.
Other sources
Malicious actors can pass step checks and potentially change the configuration of Zabbix Frontend.
— CISA
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-23134.
What is the title of the vulnerability?
The title of the vulnerability is Zabbix Frontend Improper Access Control Vulnerability.
What is the severity of CVE-2022-23134?
The severity of CVE-2022-23134 is medium with a CVSS score of 5.3.
What software is affected by CVE-2022-23134?
The Zabbix Frontend software version 5.4.0 to 5.4.8, as well as Zabbix 6.0.0-alpha1 to 6.0.0-alpha7 are affected.
How can an attacker exploit CVE-2022-23134?
An attacker can exploit CVE-2022-23134 by passing step checks in the setup.php file and potentially changing the configuration of Zabbix Frontend.
Are there any references related to CVE-2022-23134?
Yes, you can find references related to CVE-2022-23134 on the Debian LTS and Fedora Project mailing lists.