CVE-2022-22704: Critical severity zabbix agent 2 vulnerability
The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that systemd would (in effect) determine part of the configuration.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-22704?
CVE-2022-22704 is a vulnerability in the zabbix-agent2 package before version 5.4.9-r1 for Alpine Linux that allows privilege escalation to root.
What is the severity of CVE-2022-22704?
CVE-2022-22704 has a severity rating of 9.8 out of 10, indicating a critical vulnerability.
How does CVE-2022-22704 allow privilege escalation?
CVE-2022-22704 allows privilege escalation by incorrectly expecting that systemd would determine part of the configuration.
Which software versions are affected by CVE-2022-22704?
The zabbix-agent2 package versions before 5.4.9-r1 for Alpine Linux are affected by CVE-2022-22704.
How can I fix CVE-2022-22704?
To fix CVE-2022-22704, update the zabbix-agent2 package to version 5.4.9-r1 or later for Alpine Linux.