CVE-2022-39289
published 2022-10-07CVE-2022-39289: ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes Database Log contents to user…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.75%
50.7th percentile
ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes Database Log contents to user without privileges, allows insertion, modification, deletion of logs without System Privileges. Users are advised yo upgrade as soon as possible. Users unable to upgrade should disable database logging.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zoneminder | < zoneminder 1.36.31+dfsg1-1 (bookworm) | zoneminder 1.36.31+dfsg1-1 (bookworm) |
| zoneminder | zoneminder | < 1.36.27 | 1.36.27 |
| zoneminder | zoneminder | <= 1.36.27 | — |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | >= 0 < 1.36.31+dfsg1-1 | 1.36.31+dfsg1-1 |
| zoneminder | zoneminder | >= 0 < 1.36.31+dfsg1-1 | 1.36.31+dfsg1-1 |
| zoneminder | zoneminder | >= 0 < 1.36.31+dfsg1-1 | 1.36.31+dfsg1-1 |
| zoneminder | zoneminder | >= 1.37.0 < 1.37.24 | 1.37.24 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv7.5HIGH
vendor_debian9.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
ZoneMinder API access control (GHSA-mpcx-3gvh-9488 / EUVD-2022-41787)
vuldb·2026-06-29·CVSS 7.5
CVE-2022-39289 [HIGH] ZoneMinder API access control (GHSA-mpcx-3gvh-9488 / EUVD-2022-41787)
A vulnerability marked as critical has been reported in ZoneMinder. This affects an unknown part of the component API. Performing a manipulation results in improper access controls.
This vulnerability was named CVE-2022-39289. The attack may be initiated remotely. There is no available exploit.
Applying a patch is the recommended action to fix this issue.
OSV
CVE-2022-39289: ZoneMinder is a free, open source Closed-circuit television software application
osv·2022-10-07·CVSS 7.5
CVE-2022-39289 [HIGH] CVE-2022-39289: ZoneMinder is a free, open source Closed-circuit television software application
ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes Database Log contents to user without privileges, allows insertion, modification, deletion of logs without System Privileges. Users are advised yo upgrade as soon as possible. Users unable to upgrade should disable database logging.
Debian
CVE-2022-39289: zoneminder - ZoneMinder is a free, open source Closed-circuit television software application...
vendor_debian·2022·CVSS 9.1
CVE-2022-39289 [CRITICAL] CVE-2022-39289: zoneminder - ZoneMinder is a free, open source Closed-circuit television software application...
ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes Database Log contents to user without privileges, allows insertion, modification, deletion of logs without System Privileges. Users are advised yo upgrade as soon as possible. Users unable to upgrade should disable database logging.
Scope: local
bookworm: resolved (fixed in 1.36.31+dfsg1-1)
bullseye: open
forky: resolved (fixed in 1.36.31+dfsg1-1)
sid: resolved (fixed in 1.36.31+dfsg1-1)
trixie: resolved (fixed in 1.36.31+dfsg1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/ZoneMinder/zoneminder/commit/34ffd92bf123070cab6c83ad4cfe6297dd0ed0b4https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-mpcx-3gvh-9488https://github.com/ZoneMinder/zoneminder/commit/34ffd92bf123070cab6c83ad4cfe6297dd0ed0b4https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-mpcx-3gvh-9488
2022-10-07
Published