CVE-2022-23132

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
13/01/2022
Last modified:
03/11/2025

Description

During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix Proxy or Server processes can bypass file read, write and execute permissions check on the file system level

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* 4.0.0 (including) 4.0.36 (including)
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* 5.0.0 (including) 5.0.18 (including)
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* 5.4.0 (including) 5.4.8 (including)
cpe:2.3:a:zabbix:zabbix:6.0.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:6.0.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:6.0.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:6.0.0:alpha4:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:6.0.0:alpha5:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:6.0.0:alpha6:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:6.0.0:alpha7:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*