CVE-2022-23132
Severity CVSS v4.0:
Pending analysis
Type:
CWE-284
Improper Access Control
Publication date:
13/01/2022
Last modified:
03/11/2025
Description
During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix Proxy or Server processes can bypass file read, write and execute permissions check on the file system level
Impact
Base Score 3.x
3.30
Severity 3.x
LOW
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* | 4.0.0 (including) | 4.0.36 (including) |
| cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* | 5.0.0 (including) | 5.0.18 (including) |
| cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* | 5.4.0 (including) | 5.4.8 (including) |
| cpe:2.3:a:zabbix:zabbix:6.0.0:alpha1:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:6.0.0:alpha2:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:6.0.0:alpha3:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:6.0.0:alpha4:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:6.0.0:alpha5:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:6.0.0:alpha6:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:6.0.0:alpha7:*:*:*:*:*:* | ||
| cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6SZYHXINBKCY42ITFSNCYE7KCSF33VRA/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VB6W556GVXOKUYTASTDGL3AI7S3SJHX7/
- https://support.zabbix.com/browse/ZBX-20341
- https://lists.debian.org/debian-lts-announce/2024/10/msg00000.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6SZYHXINBKCY42ITFSNCYE7KCSF33VRA/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VB6W556GVXOKUYTASTDGL3AI7S3SJHX7/
- https://support.zabbix.com/browse/ZBX-20341



