Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-27232

Опубликовано: 01 дек. 2025
Источник: redhat
CVSS3: 6.8
EPSS Низкий

Описание

An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.

A flaw was found in Zabbix. This vulnerability allows an authenticated Zabbix Super Admin to read arbitrary files from the webserver via exploiting the oauth.authorize action, leading to potential confidentiality loss.

Отчет

This vulnerability is rated Moderate for Red Hat as an authenticated Zabbix Super Admin can read arbitrary files from the webserver. This flaw requires high privileges, specifically a Super Admin account, to exploit the oauth.authorize action, leading to potential confidentiality loss within Zabbix deployments in Community Projects.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-918
https://bugzilla.redhat.com/show_bug.cgi?id=2417984zabbix: Zabbix: Authenticated Super Admin can read arbitrary files via oauth.authorize action

EPSS

Процентиль: 15%
0.00048
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
ubuntu
4 месяца назад

An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.

CVSS3: 4.9
nvd
4 месяца назад

An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.

CVSS3: 4.9
debian
4 месяца назад

An authenticated Zabbix Super Admin can exploit the oauth.authorize ac ...

CVSS3: 4.9
github
4 месяца назад

An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.

CVSS3: 4.5
fstec
4 месяца назад

Уязвимость системы мониторинга ИТ-инфраструктуры Zabbix, связанная с недостаточной проверкой запросов на стороне сервера, позволяющая нарушителю получить доступ на чтение данных

EPSS

Процентиль: 15%
0.00048
Низкий

6.8 Medium

CVSS3