Database/Control plane, storage & DevOps

Zabbix: Unverified user login in session data (SAML SSO enabled)
CVSS 9.1CVE-2022-23131Control plane, storage & DevOpsKnown exploitedcurated
Impact
Unverified user login in session data (SAML SSO enabled) -> unauthenticated admin takeover
Who can reach it
Network (remote)
What to do
Control-plane: upgrade; rotate the Zabbix session secret
References
Related entries
- Zabbix: Unsanitized clientip in the audit logCVE-2024-22120 · ZabbixCritical
- Zabbix: Some setup.php steps reachable by unauthenticated usersCVE-2022-23134 · ZabbixLow
- Zabbix: SQL injection in CUser::addRelatedObjects reachable by ANY non-admin account with API accessCVE-2024-42327 · ZabbixCritical
- FlyteConsole (cors_proxy endpoint): FlyteConsole's cors_proxy forwards attacker-chosen URLs, so anyone who reaches theCVE-2022-24856 · FlyteConsole (cors_proxy endpoint)Critical
- CyberPower PowerPanel Business - default.cmd file upload: Unrestricted upload of a dangerous file type into default.cmdCVE-2023-25132 · CyberPower PowerPanel Business - default.cmd file uploadCritical
- HAProxy (before 2.7.3): HAProxy's HTTP/1 header parser accepts empty header field names, which can be used to makeCVE-2023-25725 · HAProxy (before 2.7.3)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.