Bug 2063279 (CVE-2022-24349, CVE-2022-24917, CVE-2022-24918, CVE-2022-24919)

Summary: CVE-2022-24349 CVE-2022-24917 CVE-2022-24919 CVE-2022-24918 zabbix: Multiple security vulnerabilities
Product: [Other] Security Response Reporter: Patrick Del Bello <pdelbell>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED UPSTREAM QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: bennie.joubert, dan, gwync, mstevens, orion, volker27
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2022-03-11 21:32:17 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2063280, 2063281, 2063282    
Bug Blocks:    

Description Patrick Del Bello 2022-03-11 17:20:57 UTC
Multiople Vulnerabilities found under Zabbix affecting Frontend (4.0.0-4.0.38, 5.0.0-5.0.20, 5.4.0-5.4.10, 6.0)

CVE-2022-24349

An authenticated user can create a link with reflected XSS payload for actions’ pages, and send it to other users. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim. This attack can be implemented with the help of social engineering and expiration of a number of factors - an attacker should have authorized access to the Zabbix Frontend and allowed network connection between a malicious server and victim’s computer, understand attacked infrastructure, be recognized by the victim as a trustee and use trusted communication channel.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-24349
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24349
https://support.zabbix.com/browse/ZBX-20680

-

CVE-2022-24919

An authenticated user can create a link with reflected Javascript code inside it for graphs’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim during social engineering attacks.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-24919
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24919
https://support.zabbix.com/browse/ZBX-20680

-

CVE-2022-24918

An authenticated user can create a link with reflected Javascript code inside it for items’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim during social engineering attacks.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-24918
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24918
https://support.zabbix.com/browse/ZBX-20680

-

CVE-2022-24917

An authenticated user can create a link with reflected Javascript code inside it for services’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim during social engineering attacks.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-24917
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24917
https://support.zabbix.com/browse/ZBX-20680

Comment 1 Patrick Del Bello 2022-03-11 17:21:24 UTC
Created zabbix tracking bugs for this issue:

Affects: fedora-all [bug 2063281]


Created zabbix40 tracking bugs for this issue:

Affects: epel-all [bug 2063280]


Created zabbix50 tracking bugs for this issue:

Affects: epel-all [bug 2063282]

Comment 2 Product Security DevOps Team 2022-03-11 21:32:16 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.