CVE-2022-23134

NameCVE-2022-23134
DescriptionAfter the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-2914-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
zabbix (PTS)buster1:4.0.4+dfsg-1fixed
buster (security)1:4.0.4+dfsg-1+deb10u4fixed
bullseye1:5.0.8+dfsg-1fixed
bookworm1:6.0.14+dfsg-1fixed
sid, trixie1:6.0.25+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
zabbixsourcestretch1:3.0.32+dfsg-0+deb9u2DLA-2914-1
zabbixsourcebuster(not affected)
zabbixsourcebullseye(not affected)
zabbixsource(unstable)1:6.0.7+dfsg-2

Notes

[bullseye] - zabbix <not-affected> (Vulnerable code not present; session data not stored in cookies)
[buster] - zabbix <not-affected> (Vulnerable code not present)
https://support.zabbix.com/browse/ZBX-20384
https://git.zabbix.com/projects/ZBX/repos/zabbix/commits/aa0fecfbcc9794bc00206630a7424575dfc944df (5.0.19rc2)
4.0 and 5.0 are not affected: https://support.zabbix.com/browse/ZBX-20384?focusedCommentId=648239&page=com.atlassian.jira.plugin.system.issuetabpanels%3Acomment-tabpanel#comment-648239

Search for package or bug name: Reporting problems