MEDIUM

CVE-2022-23134

Fedoraproject Fedora 2022-01-13 CVSS v3.1
CVSS
5.3
KEV

Description

After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

Summary dbcve.org

Zabbix Frontend setup.php contains an access control flaw where certain configuration steps remain accessible to unauthenticated users after the initial setup process completes. This allows attackers to bypass step verification checks and potentially modify frontend configuration settings.

Mitigation

Restrict access to setup.php to authenticated super-administrators only, or disable/remove setup.php after initial configuration is complete. Verify that all setup steps require proper authentication.

Patch Commit

Weakness (CWE)

CWE-284 Improper Access Control
CWE-287 Improper Authentication

EPSS Score

95.26%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE