CVE-2022-23132: Incorrect permissions of [/var/run/zabbix] forces dac_override
During Zabbix installation from RPM, DACOVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix Proxy or Server processes can bypass file read, write and execute permissions check on the file system level
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is CVE-2022-23132?
CVE-2022-23132 is a vulnerability that allows Zabbix Proxy or Server processes to bypass file permissions check on the file system level during Zabbix installation from RPM.
How does CVE-2022-23132 affect Zabbix?
CVE-2022-23132 affects Zabbix versions 4.0.0 to 4.0.36, 5.0.0 to 5.0.18, and 5.4.0 to 5.4.8.
What is the severity of CVE-2022-23132?
CVE-2022-23132 has a severity score of 7.3 (high).
How can I fix CVE-2022-23132?
To fix CVE-2022-23132, it is recommended to upgrade to a patched version of Zabbix that addresses the vulnerability.
Where can I find more information about CVE-2022-23132?
You can find more information about CVE-2022-23132 on the following references: [reference 1](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6SZYHXINBKCY42ITFSNCYE7KCSF33VRA/), [reference 2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VB6W556GVXOKUYTASTDGL3AI7S3SJHX7/), [reference 3](https://support.zabbix.com/browse/ZBX-20341).