A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.
2025-10-03T12:15:43.790
2025-10-08T14:54:42.290
Analyzed
CVSSv3.1: 6.5 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | zabbix | zabbix | < 6.0.41 | Yes |
| Application | zabbix | zabbix | < 7.0.17 | Yes |
| Application | zabbix | zabbix | < 7.2.11 | Yes |
| Application | zabbix | zabbix | 7.4.0 | Yes |