Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to them.
History

Mon, 15 Sep 2025 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Mon, 15 Sep 2025 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Zabbix
Zabbix zabbix
Vendors & Products Zabbix
Zabbix zabbix

Fri, 12 Sep 2025 12:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 12 Sep 2025 10:45:00 +0000

Type Values Removed Values Added
Description Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to them.
Title API hostprototype.get lists data to users with insufficient authorization.
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zabbix

Published: 2025-09-12T10:33:17.753Z

Updated: 2025-09-15T18:48:19.882Z

Reserved: 2025-02-20T11:40:38.480Z

Link: CVE-2025-27238

cve-icon Vulnrichment

Updated: 2025-09-12T11:54:32.704Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-12T11:15:31.517

Modified: 2025-09-15T19:15:34.553

Link: CVE-2025-27238

cve-icon Redhat

No data.