Permissions, Privileges, and Access Controls in Zabbix - CVE-2022-23132

 

Permissions, Privileges, and Access Controls in Zabbix - CVE-2022-23132

Published: February 23, 2022


Vulnerability identifier: #VU60812
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-23132
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to during Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix Proxy or Server processes can bypass file read, write and execute permissions check on the file system level.


Affected software

Zabbix
Fedora
zabbix40
zabbix50
zabbix

How to mitigate CVE-2022-23132

Install updates from vendor's website.

Zabbix - addressed in versions 5.0.19 rc1, 5.4.9 rc1
zabbix40 - update to 4.0.37-1.el7
zabbix50 - update to 5.0.19-1.el7
zabbix - addressed in versions 5.0.19-1.fc34, 5.0.19-1.fc35, 5.0-820220117005358.9edba152

External References

Related Security Bulletins