CVE-2022-23133

Name
CVE-2022-23133
Description
An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored by an authenticated malicious actor and other users try to search for groups during new host creation, the XSS payload will fire and the actor can steal session cookies and perform session hijacking to impersonate users or take over their accounts.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://support.zabbix.com/browse/ZBX-20388
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6SZYHXINBKCY42ITFSNCYE7KCSF33VRA/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VB6W556GVXOKUYTASTDGL3AI7S3SJHX7/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6SZYHXINBKCY42ITFSNCYE7KCSF33VRA/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VB6W556GVXOKUYTASTDGL3AI7S3SJHX7/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* zabbix >= 5.0.0 <= 5.0.18
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* zabbix >= 5.4.0 <= 5.4.8
cpe:2.3:a:zabbix:zabbix:6.0.0:alpha1:*:*:*:*:*:* zabbix == None == 6.0.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
zabbix edge-community 6.0.0-r0 Kevin Daudt <kdaudt@alpinelinux.org> possibly vulnerable