Description
A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.
Problem types
CWE-863: Incorrect Authorization
Product status
6.0.38
7.0.9
7.2.3
7.4.0 before 7.4.1
Credits
Zabbix wants to thank yannapostrophe and exod for submitting this report on the HackerOne bug bounty platform.
References
support.zabbix.com/browse/ZBX-27060