← Back

CVE-2022-23132

nvd nist
Published: Jan 13, 2022Modified: Nov 3, 2025

JSON object

Loading...
7.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Exploitability: 3.9 / Impact: 3.4
Source: NVD

Description

During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix Proxy or Server processes can bypass file read, write and execute permissions check on the file system level

Affected (12)

1 product
Zabbix
1 product
Fedora
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Zabbix
From 4.0.0 to 4.0.36
From 5.0.0 to 5.0.18
From 5.4.0 to 5.4.8
Version 6.0.0 alpha1
Version 6.0.0 alpha2
Version 6.0.0 alpha3
Version 6.0.0 alpha4
Version 6.0.0 alpha5
Version 6.0.0 alpha6
Version 6.0.0 alpha7
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 34
Version 35

Timeline

No history available yet.