Zabbix Sia Zabbix是拉脱维亚Zabbix SIA(Zabbix Sia)公司的一套开源的监控系统。该系统支持网络监控、服务器监控、云监控和应用监控等。 Zabbix 存在安全漏洞,该漏洞源于在从 RPM 安装 Zabbix 期间,DAC_OVERRIDE SELinux 功能用于访问[/var/run/zabbix]文件夹中的 PID 文件。在这种情况下,Zabbix Proxy 或 Server 进程可以绕过文件系统级别的文件读取、写入和执行权限检查。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Zabbix | Proxy, Server | 4.0.0 - 4.0.36 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-23131 | 9.1 CRITICAL | Unsafe client-side session storage leading to authentication bypass/instance takeover via |
| CVE-2022-23133 | 6.3 MEDIUM | Stored XSS in host groups configuration window in Zabbix Frontend |
| CVE-2022-23134 | 3.7 LOW | Possible view of the setup pages by unauthenticated users if config file already exists |
No comments yet