Loading HuntDB...

GHSA-4g73-3mxf-j47w

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and gain admin access to Zabbix Frontend. To perform the attack, SAML authentication is required to be enabled and the actor has to know the username of Zabbix user (or use the guest account, which is disabled by default).

Related CVEs

Key Information

GHSA ID
GHSA-4g73-3mxf-j47w
Published
January 14, 2022 12:02 AM
Last Modified
March 12, 2025 9:31 PM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 27, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.