yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2022-46768
Component Overview
Vulnerability Overview
Name
CVE-2022-46768
Source
NVD (
link
)
Debian (
link
)
Description
Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper validation for URL parameters before reading the files.
CWEs
CWE-20
CWE-20
Published Date
Dec 15, 2022
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://support.zabbix.com/browse/ZBX-22087
Patch
https://support.zabbix.com/browse/ZBX-22087
Patch
Analysis
#
Affected Component
Analysis
zabbix
Patched
Vulnerability Ratings
#
5.9
CVSSv31
5.9
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
zabbix
buildroot
2025.02.x
7.2.13
Not Affected
zabbix
buildroot
master
7.2.13
Not Affected
zabbix
openwrt
master
7.0.26-r1
Not Affected
zabbix
openwrt
openwrt-25.12
7.0.25-r1
Not Affected
zabbix
yocto
master
7.0.24
Not Affected
zabbix
yocto
scarthgap
6.2.9
Not Affected
Resolved with patches
#
zabbix (yocto:kirkstone)
#
Title
Author
Resolve
1
[DEV-2283] added validation of the scheduled report
Changqing Li <changqing.li@windriver.com>
CVE-2022-46768