← Back

CVE-2022-23134

Published: Jan 13, 2022Modified: Oct 30, 2025CISA KEV

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

Affected (12)

1 product
Zabbix
1 product
Fedora
1 product
Debian Linux
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Zabbix
From 5.4.0 to 5.4.8
Version 6.0.0 alpha1
Version 6.0.0 alpha2
Version 6.0.0 alpha3
Version 6.0.0 alpha4
Version 6.0.0 alpha5
Version 6.0.0 alpha6
Version 6.0.0 alpha7
Version 6.0.0 beta1
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 34
Version 35
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0

Timeline

No history available yet.