7.5

CVE-2022-23132

During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix Proxy or Server processes can bypass file read, write and execute permissions check on the file system level

Data is provided by the National Vulnerability Database (NVD)
ZabbixZabbix Version >= 4.0.0 <= 4.0.36
ZabbixZabbix Version >= 5.0.0 <= 5.0.18
ZabbixZabbix Version >= 5.4.0 <= 5.4.8
ZabbixZabbix Version6.0.0 Updatealpha1
ZabbixZabbix Version6.0.0 Updatealpha2
ZabbixZabbix Version6.0.0 Updatealpha3
ZabbixZabbix Version6.0.0 Updatealpha4
ZabbixZabbix Version6.0.0 Updatealpha5
ZabbixZabbix Version6.0.0 Updatealpha6
ZabbixZabbix Version6.0.0 Updatealpha7
FedoraprojectFedora Version34
FedoraprojectFedora Version35
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.1% 0.292
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.3 3.9 3.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
security@zabbix.com 3.3 0.8 2.5
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CWE-732 Incorrect Permission Assignment for Critical Resource

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.