After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.
CVSS Details
- CVSS 3.1 Base Score: 3.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade zabbix | Feb 9, 2022 | Jan 13, 2022 |
| Suse | — | Upgrade zabbix-proxy-sqliteUpgrade zabbix-java-gatewayUpgrade zabbix-proxy-postgresqlUpgrade zabbix-proxy-mysqlUpgrade zabbix-server-mysqlUpgrade zabbix-phpfrontendUpgrade zabbix-agentUpgrade zabbix-proxyUpgrade zabbix-server-postgresqlUpgrade zabbix-server | Feb 17, 2022 | Jan 13, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub