CVE-2022-22704

The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that systemd would (in effect) determine part of the configuration.
References
Link Resource
https://gitlab.alpinelinux.org/alpine/aports/-/issues/13368 Exploit Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:zabbix:zabbix-agent2:*:*:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix-agent2:5.4.9:-:*:*:*:*:*:*
cpe:2.3:o:alpinelinux:alpine_linux:-:*:*:*:*:*:*:*

History

08 Aug 2023, 14:21

Type Values Removed Values Added
CWE CWE-269 CWE-909

31 Jan 2022, 18:09

Type Values Removed Values Added
CPE cpe:2.3:a:zabbix:zabbiz-agent2:*:*:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbiz-agent2:5.4.9:-:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix-agent2:5.4.9:-:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix-agent2:*:*:*:*:*:*:*:*
First Time Zabbix zabbix-agent2

18 Jan 2022, 17:31

Type Values Removed Values Added
References (MISC) https://gitlab.alpinelinux.org/alpine/aports/-/issues/13368 - Exploit, Vendor Advisory (MISC) https://gitlab.alpinelinux.org/alpine/aports/-/issues/13368 - Exploit, Issue Tracking, Third Party Advisory
CPE cpe:2.3:o:alpinelinux:alpine_linux:*:*:*:*:*:*:*:*
cpe:2.3:o:alpinelinux:alpine_linux:5.4.9:-:*:*:*:*:*:*
cpe:2.3:o:alpinelinux:alpine_linux:5.4.9:r1:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbiz-agent2:*:*:*:*:*:*:*:*
cpe:2.3:o:alpinelinux:alpine_linux:-:*:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbiz-agent2:5.4.9:-:*:*:*:*:*:*
First Time Zabbix zabbiz-agent2
Zabbix

13 Jan 2022, 19:23

Type Values Removed Values Added
CWE CWE-269
CPE cpe:2.3:o:alpinelinux:alpine_linux:*:*:*:*:*:*:*:*
cpe:2.3:o:alpinelinux:alpine_linux:5.4.9:-:*:*:*:*:*:*
cpe:2.3:o:alpinelinux:alpine_linux:5.4.9:r1:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 10.0
v3 : 9.8
First Time Alpinelinux
Alpinelinux alpine Linux
References (MISC) https://gitlab.alpinelinux.org/alpine/aports/-/issues/13368 - (MISC) https://gitlab.alpinelinux.org/alpine/aports/-/issues/13368 - Exploit, Vendor Advisory

06 Jan 2022, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-01-06 05:15

Updated : 2023-12-10 14:09


NVD link : CVE-2022-22704

Mitre link : CVE-2022-22704

CVE.ORG link : CVE-2022-22704


JSON object : View

Products Affected

alpinelinux

  • alpine_linux

zabbix

  • zabbix-agent2
CWE
CWE-909

Missing Initialization of Resource