Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-23133
HistoryJan 13, 2022 - 12:00 a.m.

CVE-2022-23133

2022-01-1300:00:00
ubuntu.com
ubuntu.com
7

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

6.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

0.001 Low

EPSS

Percentile

28.8%

An authenticated user can create a hosts group from the configuration with
XSS payload, which will be available for other users. When XSS is stored by
an authenticated malicious actor and other users try to search for groups
during new host creation, the XSS payload will fire and the actor can steal
session cookies and perform session hijacking to impersonate users or take
over their accounts.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu22.04noarchzabbix< anyUNKNOWN

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

6.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

0.001 Low

EPSS

Percentile

28.8%