openSUSE-SU-2022:0036-1
Dashboard / Vulnerabilities / openSUSE-SU-2022:0036-1
openSUSE-SU-2022:0036-1
Summary: Security update for zabbix
Details: This update for zabbix fixes the following issues: - Updated to latest realease 4.0.37. Security issues fixed: - CVE-2022-23134: Fixed possible view of the setup pages by unauthenticated users if config file already exists (boo#1194681). - CVE-2021-27927: Fixed CSRF protection mechanism inside CControllerAuthenticationUpdate controller (boo#1183014). - CVE-2020-15803: Fixed stored XSS in the URL Widget (boo#1174253). Bugfixes: - boo#1181400: Added hardening to systemd service(s) - boo#1144018: Restructured for easier maintenance because FATE#324346
References: https://lists.opensuse.org/archives/list/[email protected]/thread/EDFZEEJCPRPPDEWV6JULRJZVSQCMYOEY/, https://bugzilla.suse.com/1144018, https://bugzilla.suse.com/1174253, https://bugzilla.suse.com/1181400, https://bugzilla.suse.com/1183014, https://bugzilla.suse.com/1194681, https://www.suse.com/security/cve/CVE-2020-15803, https://www.suse.com/security/cve/CVE-2021-27927, https://www.suse.com/security/cve/CVE-2022-23134
Affected packages
Package
Name: zabbix
Purl: pkg:rpm/opensuse/zabbix&distro=openSUSE%20Leap%2015.3
Affected ranges
Type: ECOSYSTEM
Events:
