{"id":"openSUSE-SU-2022:0036-1","summary":"Security update for zabbix","details":"This update for zabbix fixes the following issues:\n\n- Updated to latest realease 4.0.37.\n\nSecurity issues fixed:\n\n- CVE-2022-23134: Fixed possible view of the setup pages by unauthenticated users if config file already exists (boo#1194681).\n- CVE-2021-27927: Fixed CSRF protection mechanism inside CControllerAuthenticationUpdate controller (boo#1183014).\n- CVE-2020-15803: Fixed stored XSS in the URL Widget (boo#1174253).\n\nBugfixes:\n\n- boo#1181400: Added hardening to systemd service(s)\n- boo#1144018: Restructured for easier maintenance because FATE#324346\n","modified":"2026-03-11T07:33:23.077214Z","published":"2022-02-16T09:04:51Z","related":["CVE-2020-15803","CVE-2021-27927","CVE-2022-23134"],"upstream":["CVE-2020-15803","CVE-2021-27927","CVE-2022-23134"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/EDFZEEJCPRPPDEWV6JULRJZVSQCMYOEY/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1144018"},{"type":"REPORT","url":"https://bugzilla.suse.com/1174253"},{"type":"REPORT","url":"https://bugzilla.suse.com/1181400"},{"type":"REPORT","url":"https://bugzilla.suse.com/1183014"},{"type":"REPORT","url":"https://bugzilla.suse.com/1194681"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15803"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-27927"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-23134"}],"affected":[{"package":{"name":"zabbix","ecosystem":"openSUSE:Leap 15.3","purl":"pkg:rpm/opensuse/zabbix&distro=openSUSE%20Leap%2015.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.0.37-lp153.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"zabbix-agent":"4.0.37-lp153.2.3.1","zabbix-proxy-mysql":"4.0.37-lp153.2.3.1","zabbix-proxy-postgresql":"4.0.37-lp153.2.3.1","zabbix-java-gateway":"4.0.37-lp153.2.3.1","zabbix-phpfrontend":"4.0.37-lp153.2.3.1","zabbix-proxy-sqlite":"4.0.37-lp153.2.3.1","zabbix-proxy":"4.0.37-lp153.2.3.1","zabbix-server-mysql":"4.0.37-lp153.2.3.1","zabbix-server-postgresql":"4.0.37-lp153.2.3.1","zabbix-server":"4.0.37-lp153.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:0036-1.json"}}],"schema_version":"1.7.5"}