Low severity3.3NVD Advisory· Published Jan 13, 2022· Updated Jun 17, 2026
CVE-2022-23132
CVE-2022-23132
Description
During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix Proxy or Server processes can bypass file read, write and execute permissions check on the file system level
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*range: >=4.0.0,<=4.0.36
- cpe:2.3:a:zabbix:zabbix:6.0.0:alpha1:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:6.0.0:alpha2:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:6.0.0:alpha3:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:6.0.0:alpha4:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:6.0.0:alpha5:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:6.0.0:alpha6:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:6.0.0:alpha7:*:*:*:*:*:*
- (no CPE)
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- Zabbix/Proxy, Serverv5Range: 4.0.0 - 4.0.36
Patches
Vulnerability mechanics
References
4- support.zabbix.com/browse/ZBX-20341nvdIssue TrackingPatchVendor Advisory
- lists.debian.org/debian-lts-announce/2024/10/msg00000.htmlnvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6SZYHXINBKCY42ITFSNCYE7KCSF33VRA/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VB6W556GVXOKUYTASTDGL3AI7S3SJHX7/nvd
News mentions
0No linked articles in our index yet.