← back
CVE-2022-23131criticalunder attackCWE-290

Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.1epss 96%
from disclosure to weapon36 days
Published on NVDJan 13
1st PoC+36d
CISA KEV+40d
exploitation probability
96%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
38 public exploit(s)
Action required by CISAfederal deadline: 2022-03-08

Apply updates per vendor instructions.

Researched and written with AI from the vendor advisory and public analysis, with the sources above. Always confirm the fixed version in the official advisory before acting.
In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and gain admin access to Zabbix Frontend. To perform the attack, SAML authentication is required to be enabled and the actor has to know the username of Zabbix user (or use the guest account, which is disabled by default).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
Zabbix · Frontend
public PoCs found38
githubgithub.com/Mr-xn/cve-2022-23131154githubgithub.com/jweny/CVE-2022-2313195githubgithub.com/L0ading-x/cve-2022-2313129githubgithub.com/kh4sh3i/CVE-2022-2313115githubgithub.com/Kazaf6s/CVE-2022-2313111githubgithub.com/random-robbie/cve-2022-23131-exp8githubgithub.com/SCAMagic/CVE-2022-23131poc-exp-zabbix-8githubgithub.com/fork-bombed/CVE-2022-231314githubgithub.com/1mxml/CVE-2022-231313githubgithub.com/davidzzo23/CVE-2022-231313githubgithub.com/pykiller/CVE-2022-231312githubgithub.com/Vulnmachines/Zabbix-CVE-2022-231312githubgithub.com/trganda/CVE-2022-231311githubgithub.com/clearcdq/Zabbix-SAML-SSO-_CVE-2022-231311githubgithub.com/wr0x00/cve-2022-231311githubgithub.com/zwjjustdoit/cve-2022-231311githubgithub.com/Fa1c0n35/zabbix-cve-2022-231311githubgithub.com/qq1549176285/CVE-2022-231310githubgithub.com/Arrnitage/CVE-2022-23131_exp0githubgithub.com/r10lab/CVE-2022-231310githubgithub.com/dagowda/Zabbix-cve-2022-23131-SSO-bypass0githubgithub.com/Chaelsoo/CVE-2022-23131-Wrappers0vulncheckvulncheck.com/xdb/26336c5bf065unverifiedvulncheckvulncheck.com/xdb/87a03dbcb4d4unverifiedvulncheckvulncheck.com/xdb/a91a49f498d6unverifiedvulncheckvulncheck.com/xdb/6bf41d728409unverifiedvulncheckvulncheck.com/xdb/0eca8abcd488unverifiedvulncheckvulncheck.com/xdb/4bcdfe77a9b2unverifiedvulncheckvulncheck.com/xdb/4fc1fafc24ecunverifiedvulncheckvulncheck.com/xdb/004f3023163cunverifiedvulncheckvulncheck.com/xdb/099f2ba1828aunverifiedvulncheckvulncheck.com/xdb/3159b6a83e89unverifiedvulncheckvulncheck.com/xdb/57651461a50bunverifiedvulncheckvulncheck.com/xdb/e46f3b30212funverifiedvulncheckvulncheck.com/xdb/63bde8d02b8funverifiedvulncheckvulncheck.com/xdb/9edf8d0fe243unverifiedvulncheckvulncheck.com/xdb/f0dbb969817bunverifiedvulncheckvulncheck.com/xdb/b0a2be43d1ecunverified
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.