VYPR
Low severity3.3NVD Advisory· Published Jan 13, 2022· Updated Jun 17, 2026

CVE-2022-23132

CVE-2022-23132

Description

During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix Proxy or Server processes can bypass file read, write and execute permissions check on the file system level

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

12
  • Zabbix/Zabbix9 versions
    cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*+ 8 more
    • cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*range: >=4.0.0,<=4.0.36
    • cpe:2.3:a:zabbix:zabbix:6.0.0:alpha1:*:*:*:*:*:*
    • cpe:2.3:a:zabbix:zabbix:6.0.0:alpha2:*:*:*:*:*:*
    • cpe:2.3:a:zabbix:zabbix:6.0.0:alpha3:*:*:*:*:*:*
    • cpe:2.3:a:zabbix:zabbix:6.0.0:alpha4:*:*:*:*:*:*
    • cpe:2.3:a:zabbix:zabbix:6.0.0:alpha5:*:*:*:*:*:*
    • cpe:2.3:a:zabbix:zabbix:6.0.0:alpha6:*:*:*:*:*:*
    • cpe:2.3:a:zabbix:zabbix:6.0.0:alpha7:*:*:*:*:*:*
    • (no CPE)
  • cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
  • Zabbix/Proxy, Serverv5
    Range: 4.0.0 - 4.0.36

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.