CVE-2023-32723Incorrect Permission Assignment in Zabbix

Severity
9.1CRITICALNVD
CNA8.5
EPSS
0.1%
top 68.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 12

Description

Request to LDAP is sent before user permissions are checked.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages4 packages

NVDzabbix/zabbix4.0.04.0.19+4
debiandebian/zabbix< zabbix 1:5.0.0+dfsg-1 (bookworm)
Debianzabbix/zabbix< 1:5.0.0+dfsg-1+3
CVEListV5zabbix/zabbix4.0.04.0.19rc1+2

🔴Vulnerability Details

3
CVEList
Inefficient permission check in class CControllerAuthenticationUpdate2023-10-12
GHSA
GHSA-34w2-qwhq-wprv: Request to LDAP is sent before user permissions are checked2023-10-12
OSV
CVE-2023-32723: Request to LDAP is sent before user permissions are checked2023-10-12

📋Vendor Advisories

1
Debian
CVE-2023-32723: zabbix - Request to LDAP is sent before user permissions are checked.2023