Executive brief
Zabbix Frontend allows an unauthenticated attacker to bypass authentication and gain administrative access when SAML SSO is enabled. The vulnerability exists because session data, specifically the user login, is not properly verified, allowing for client-side session modification.
Affected products
- Zabbix Zabbix Frontend 5.4.0 - 5.4.8, 6.0.0 alpha1
Timeline
- 2022-01-13: disclosed: NVD Published Date
- 2022-02-22: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-02-22: advisory: Published date listed in advisory header