Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-27232

Опубликовано: 01 дек. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 4.9

Описание

An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.

РелизСтатусПримечание
devel

needs-triage

esm-apps-legacy/xenial

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/resolute

needs-triage

esm-apps/xenial

ignored

end of ESM support, was needs-triage
esm-infra-legacy/trusty

needs-triage

jammy

needs-triage

noble

DNE

Показывать по

EPSS

Процентиль: 21%
0.00297
Низкий

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
redhat
8 месяцев назад

An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.

CVSS3: 4.9
nvd
8 месяцев назад

An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.

CVSS3: 4.9
debian
8 месяцев назад

An authenticated Zabbix Super Admin can exploit the oauth.authorize ac ...

CVSS3: 4.9
github
8 месяцев назад

An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.

CVSS3: 4.5
fstec
8 месяцев назад

Уязвимость системы мониторинга ИТ-инфраструктуры Zabbix, связанная с недостаточной проверкой запросов на стороне сервера, позволяющая нарушителю получить доступ на чтение данных

EPSS

Процентиль: 21%
0.00297
Низкий

4.9 Medium

CVSS3