PT-2022-1639 · Zabbix+1 · Zabbix+1
Thomas Chauchefoin
·
Published
2019-05-20
·
Updated
2026-03-06
·
CVE-2022-23131
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zabbix (affected versions not specified)
Description
The issue is related to the SAML SSO authentication in Zabbix. When SAML SSO authentication is enabled, a malicious actor can modify session data because the user login stored in the session is not verified. This can allow an unauthenticated actor to escalate privileges and gain admin access to Zabbix Frontend. The attack requires SAML authentication to be enabled, and the actor must know the username of a Zabbix user or use the guest account, which is disabled by default.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Zabbix