CVE-2022-43515: X-Forwarded-For header is active by default causes access to Zabbix sites in maintenance mode
Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this way, any user will not be able to access the Zabbix Frontend while it is being maintained and possible sensitive data will be prevented from being disclosed. An attacker can bypass this protection and access the instance using IP address not listed in the defined range.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-43515?
CVE-2022-43515 is a vulnerability in Zabbix Frontend that allows unauthorized access.
What is the severity of CVE-2022-43515?
The severity of CVE-2022-43515 is critical with a score of 9.8.
How does CVE-2022-43515 impact Zabbix Frontend?
CVE-2022-43515 allows unauthorized access to Zabbix Frontend and can lead to disclosure of sensitive data.
Which versions of Zabbix Frontend are affected by CVE-2022-43515?
Versions 4.0.0 to 4.0.44, 5.0.0 to 5.0.29, 6.0.0 to 6.0.9, and 6.2.0 to 6.2.4 of Zabbix Frontend are affected by CVE-2022-43515.
How can I fix CVE-2022-43515 in Zabbix Frontend?
To fix CVE-2022-43515, update Zabbix Frontend to a version that is not vulnerable.