A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions.
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Zabbix | Zabbix | 6.0.0 (including) | 6.0.32 (excluding) | 
| Zabbix | Zabbix | 6.4.0 (including) | 6.4.17 (excluding) | 
| Zabbix | Zabbix | 7.0.0 (including) | 7.0.0 (including) | 
| Zabbix | Ubuntu | focal | * | 
| Zabbix | Ubuntu | trusty/esm | * | 
| Zabbix | Ubuntu | upstream | * |