NVD disclosure day

Published threat advisories for January 13, 2022

CVE advisoryCRITICAL

CVE-2021-45807

jpress Command Execution Vulnerability CVE-2021-45807

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A command execution vulnerability exists in jpress, a web content system, that could allow an unauthenticated attacker to run arbitrary commands. This is a critical issue if the upload functionality is reachable over the network, potentially impacting server integrity and availability.

CVE advisoryKnown Exploit

CVE-2022-23131

Zabbix Frontend Authentication Bypass and Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Zabbix Frontend, when SAML SSO is enabled, allows an unauthenticated actor to modify session data and escalate privileges to gain administrative access. This impacts organizations using Zabbix Frontend with SAML SSO configured. The business risk involves unauthorized administrative control over monit

• CISA KEV