Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2022-23133
HistoryJan 13, 2022 - 4:15 p.m.

CVE-2022-23133

2022-01-1316:15:00
Alpine Linux Development Team
security.alpinelinux.org
33
authenticated user
hosts group
xss payload
session hijacking
session cookies
impersonate users
account takeover

EPSS

0.001

Percentile

28.8%

An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored by an authenticated malicious actor and other users try to search for groups during new host creation, the XSS payload will fire and the actor can steal session cookies and perform session hijacking to impersonate users or take over their accounts.

OSVersionArchitecturePackageVersionFilename
Alpineedge-communitynoarchzabbix= 6.0.0-r0UNKNOWN

EPSS

0.001

Percentile

28.8%