Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-27236

Опубликовано: 03 окт. 2025
Источник: debian
EPSS Низкий

Описание

A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zabbixunfixedpackage

Примечания

  • https://support.zabbix.com/browse/ZBX-27060

  • Internal issue DEV-4295

  • Fixed by: https://github.com/zabbix/zabbix/commit/d9404e01005c83e91216caeebcfdbbdcbb64b4d9 (6.0.41rc1)

  • Fixed by: https://github.com/zabbix/zabbix/commit/15d30787f648e27a7bbc305a465952c279e971a0 (7.0.17rc1)

  • Fixed by: https://github.com/zabbix/zabbix/commit/7f63f05b187b87cf06694de817d93a954de05398 (7.2.11rc1)

  • Fixed by: https://github.com/zabbix/zabbix/commit/bdfa09b08bb4a5434e40e54776f3be6e615a83b3 (7.4.1rc1)

  • Fixed in: 6.0.41, 7.0.17, 7.2.11, 7.4.1

EPSS

Процентиль: 15%
0.00049
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 2 месяцев назад

A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.

CVSS3: 6.5
nvd
около 2 месяцев назад

A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.

CVSS3: 6.5
github
около 2 месяцев назад

A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.

CVSS3: 3.5
fstec
около 2 месяцев назад

Уязвимость универсальной системы мониторинга Zabbix , связанная с ошибками авторизации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 4.9
redos
26 дней назад

Множественные уязвимости zabbix-lts-agent2-plugin-mssql

EPSS

Процентиль: 15%
0.00049
Низкий