Vulnmachines / Zabbix-CVE-2022-23131

Zabbix-SAML-Bypass: CVE-2022-23131

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Zabbix-CVE-2022-23131

Zabbix-SAML-Bypass: CVE-2022-23131

Description:

Zabbix is vulnerable to Frontend Authentication Bypass Vulnerability with enabled SAML SSO authentication, due to insecure client-side session storage. On successful exploit of this issue, it allows a malicious actor to escalate privileges and unauthorized admin access to Zabbix frontend.

Affected Version: 5.4.0 – 5.4.8; 6.0.0alpha1

Dork:

http.favicon.hash:892542951

Mitigation

It is recommended to upgrade all the instances that are running with Zabbix Web Frontend to 6.0.0beta2, 5.4.9, 5.0.19, or 4.0.37

Follow us

About

Zabbix-SAML-Bypass: CVE-2022-23131