Database/Control plane, storage & DevOps

Zabbix: Some setup.php steps reachable by unauthenticated users
CVSS 3.7CVE-2022-23134Control plane, storage & DevOpsKnown exploitedcurated
Impact
Some setup.php steps reachable by unauthenticated users -> configuration change
Who can reach it
Network (remote)
What to do
Control-plane: upgrade; restrict frontend network access
References
Related entries
- Zabbix: SQL injection in CUser::addRelatedObjects reachable by ANY non-admin account with API accessCVE-2024-42327 · ZabbixCritical
- Zabbix: Unverified user login in session data (SAML SSO enabled)CVE-2022-23131 · ZabbixCritical
- Zabbix: Unsanitized clientip in the audit logCVE-2024-22120 · ZabbixCritical
- SkyPilot (sky/users/server.py, user ID derivation from username): User IDs are derived with a weak hash of theCVE-2026-13482 · SkyPilot (sky/users/server.py, user ID derivation from username)Low
- GitLab: unauthenticated GraphQL requests can read CI/CD job traces containing secret variable valuesCVE-2026-4523 · GitLab CE/EE (GraphQL API, CI/CD job traces)Low
- NATS server (TLS ciphersuite selection via CLI flags): A configuration footgun in the cluster message bus: NATSNCVD-2021-017-nats-server-tls-ciphersuite-sele · NATS server (TLS ciphersuite selection via CLI flags)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.