PT-2022-1639 · Zabbix+1 · Zabbix+1

Thomas Chauchefoin

·

Published

2019-05-20

·

Updated

2026-03-06

·

CVE-2022-23131

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zabbix (affected versions not specified)
Description The issue is related to the SAML SSO authentication in Zabbix. When SAML SSO authentication is enabled, a malicious actor can modify session data because the user login stored in the session is not verified. This can allow an unauthenticated actor to escalate privileges and gain admin access to Zabbix Frontend. The attack requires SAML authentication to be enabled, and the actor must know the username of a Zabbix user or use the guest account, which is disabled by default.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1862
ALT-PU-2020-1083
ALT-PU-2021-3617
ALT-PU-2022-2499
ALT-PU-2023-6268
BDU:2022-00884
CVE-2022-23131

Affected Products

Alt Linux
Zabbix