Zabbix.Server.pdf_report_creator.go.Information.Disclosure
Description
This indicates an attack attempt to exploit an Information Disclosure Vulnerability in ZABBIX.
The vulnerability is due to missing input validation on the url parameter in pdf_report_creator.go. A remote, unauthenticated attacker could exploit this vulnerability by sending a crafted request to a vulnerable Zabbix server. Successful exploitation of this vulnerability could lead to information disclosure from the target server.
Affected Products
ZABBIX ZABBIX prior to 6.4 (plan)
ZABBIX ZABBIX prior to 6.4.0beta5 (master)
Impact
Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://support.zabbix.com/browse/ZBX-22087
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |