After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.
CVSS Details
- CVSS 3.1 Base Score: 3.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade zabbix | Feb 9, 2022 | Jan 13, 2022 |
| Suse | — | Upgrade zabbix-proxyUpgrade zabbix-serverUpgrade zabbix-agentUpgrade zabbix-server-postgresqlUpgrade zabbix-phpfrontendUpgrade zabbix-proxy-mysqlUpgrade zabbix-server-mysqlUpgrade zabbix-proxy-postgresqlUpgrade zabbix-java-gatewayUpgrade zabbix-proxy-sqlite | Feb 17, 2022 | Jan 13, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub