#VU60811 Improper Authentication in Zabbix - CVE-2022-23131
Published: February 23, 2022 / Updated: September 20, 2024
Zabbix
Zabbix
Description
The vulnerability allows a remote attacker to bypass SAML authentication process.
The vulnerability exists due to unsafe usage of session data stored in local storage when using SAML SSO authentication. A remote attacker with knowledge of a valid username can bypass SAML SSO authentication and gain administrative access to Zabbix Frontend.
Successful exploitation of the vulnerability requires that the SAML SSO authentication is enabled (disabled by default).