Bug 2063279 (CVE-2022-24349, CVE-2022-24917, CVE-2022-24918, CVE-2022-24919) - CVE-2022-24349 CVE-2022-24917 CVE-2022-24919 CVE-2022-24918 zabbix: Multiple security vulnerabilities
Summary: CVE-2022-24349 CVE-2022-24917 CVE-2022-24919 CVE-2022-24918 zabbix: Multiple ...
Keywords:
Status: CLOSED UPSTREAM
Alias: CVE-2022-24349, CVE-2022-24917, CVE-2022-24918, CVE-2022-24919
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2063280 2063281 2063282
Blocks:
TreeView+ depends on / blocked
 
Reported: 2022-03-11 17:20 UTC by Patrick Del Bello
Modified: 2022-03-11 21:32 UTC (History)
6 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2022-03-11 21:32:17 UTC


Attachments (Terms of Use)

Description Patrick Del Bello 2022-03-11 17:20:57 UTC
Multiople Vulnerabilities found under Zabbix affecting Frontend (4.0.0-4.0.38, 5.0.0-5.0.20, 5.4.0-5.4.10, 6.0)

CVE-2022-24349

An authenticated user can create a link with reflected XSS payload for actions’ pages, and send it to other users. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim. This attack can be implemented with the help of social engineering and expiration of a number of factors - an attacker should have authorized access to the Zabbix Frontend and allowed network connection between a malicious server and victim’s computer, understand attacked infrastructure, be recognized by the victim as a trustee and use trusted communication channel.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-24349
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24349
https://support.zabbix.com/browse/ZBX-20680

-

CVE-2022-24919

An authenticated user can create a link with reflected Javascript code inside it for graphs’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim during social engineering attacks.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-24919
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24919
https://support.zabbix.com/browse/ZBX-20680

-

CVE-2022-24918

An authenticated user can create a link with reflected Javascript code inside it for items’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim during social engineering attacks.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-24918
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24918
https://support.zabbix.com/browse/ZBX-20680

-

CVE-2022-24917

An authenticated user can create a link with reflected Javascript code inside it for services’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim during social engineering attacks.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-24917
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24917
https://support.zabbix.com/browse/ZBX-20680

Comment 1 Patrick Del Bello 2022-03-11 17:21:24 UTC
Created zabbix tracking bugs for this issue:

Affects: fedora-all [bug 2063281]


Created zabbix40 tracking bugs for this issue:

Affects: epel-all [bug 2063280]


Created zabbix50 tracking bugs for this issue:

Affects: epel-all [bug 2063282]

Comment 2 Product Security DevOps Team 2022-03-11 21:32:16 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.


Note You need to log in before you can comment on or make changes to this bug.