Logo
vulnerabilityCVE-2022-43515
Name
CVE-2022-43515
Source
NVD ( link)Debian ( link)
Description
Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this way, any user will not be able to access the Zabbix Frontend while it is being maintained and possible sensitive data will be prevented from being disclosed. An attacker can bypass this protection and access the instance using IP address not listed in the defined range.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
zabbix
Patched

Vulnerability Ratings#


5.3
CVSSv31
9.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
7.2.13
Not Affected
buildroot
master
7.2.13
Not Affected
openwrt
master
7.0.26-r1
Not Affected
openwrt
openwrt-25.12
7.0.25-r1
Not Affected
yocto
master
7.0.24
Not Affected
yocto
scarthgap
6.2.9
Not Affected

Resolved with patches#


zabbix (yocto:kirkstone)

#
Title
Author
Resolve
1
[DEV-2301] fixed spoofing X-Forwarded-For request header
Changqing Li <changqing.li@windriver.com>
CVE-2022-43515