Home
MEDIUM: 6.8 CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NDefault status
unknown
7.4.0 (git)
affected
Description
An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.
Problem types
CWE-918: Server-Side Request Forgery (SSRF)
Product status
7.4.0 (git)
Credits
Zabbix wants to thank o4ncL1 for submitting this report on the HackerOne bug bounty platform.
References
support.zabbix.com/browse/ZBX-27282