Zabbix security update-CVE-2022-23131
NAME
Zabbix – Zabbix
- Platforms Affected:
Zabbix - Risk Level:
medium - CVE Type:
Authentication bypass
DESCRIPTION
CVE-2022-23131 is an authentication bypass vulnerability impacting Zabbix versions 5.4.7 and earlier. An exploit was observed in open source and a link to an exploit was shared in the underground. Additionally, a walk through demo of an exploit was shared via YouTube.
CVSS Information:
- CVSS 2.0 SCORE: 5.1
- CVSS 3.0 SCORE: 9.8
- Exploit Disclosed in the Public:
true - Exploit Weaponised:
true - PoC Link:
hXXps://github[.]com/Mr-xn/cve-2022-23131
MITIGATION
Zabbix addressed the vulnerability in a security advisory with updated versions.
- Reference Link:
https://support.zabbix.com/browse/ZBX-20350 - Patch Available:
available
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.