Home
LOW: 2.1 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:NDefault status
unknown
6.0.38 (git)
affected
7.0.9 (git)
affected
7.2.3 (git)
affected
7.4.0 (git) before 7.4.1
affected
Description
A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.
Problem types
CWE-863: Incorrect Authorization
Product status
6.0.38 (git)
7.0.9 (git)
7.2.3 (git)
7.4.0 (git) before 7.4.1
Credits
Zabbix wants to thank yannapostrophe and exod for submitting this report on the HackerOne bug bounty platform.
References
support.zabbix.com/browse/ZBX-27060