Zabbix
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*
- >= 6.0.38, <= 6.0.40
- >= 7.0.9, <= 7.0.16
- >= 7.2.3, <= 7.2.10
- 7.4.0
A user information disclosure vulnerability has been identified in Zabbix versions 6.0.38 through 6.0.40, 7.0.9 through 7.0.16, 7.2.3 through 7.2.10, and 7.4.0. This vulnerability allows regular Zabbix users to search for other users in their group through the Zabbix API. By selecting fields that they do not have permission to view, users can inadvertently data-mine certain field values from other users.
Exploitation of this vulnerability could lead to unauthorized access to user information that the requester is not permitted to view.
Users can update to Zabbix versions 6.0.41, 7.0.17, 7.2.11, or 7.4.1 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.