ALT-PU-2022-1975-1
Closed vulnerabilities
Published: 2022-05-09
BDU:2023-01711
Уязвимость универсальной системы мониторинга Zabbix, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю оказать воздействие на целостность данных
Severity: MEDIUM (5.4)
Vector: AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Severity: MEDIUM (4.9)
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N
References:
Published: 2022-07-06
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2022-35229
An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict.
Severity: LOW (3.5)
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N
Severity: MEDIUM (5.4)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
References:
- https://lists.debian.org/debian-lts-announce/2023/04/msg00013.html
- https://lists.debian.org/debian-lts-announce/2023/08/msg00027.html
- https://support.zabbix.com/browse/ZBX-21306
- https://lists.debian.org/debian-lts-announce/2023/04/msg00013.html
- https://lists.debian.org/debian-lts-announce/2023/08/msg00027.html
- https://support.zabbix.com/browse/ZBX-21306