Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to them.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-29034 Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to them.
Fixes

Solution

Update the affected components to their respective fixed versions.


Workaround

Make sure there are no Zabbix users without a user group.

History

Wed, 08 Oct 2025 15:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Mon, 15 Sep 2025 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Mon, 15 Sep 2025 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Zabbix
Zabbix zabbix
Vendors & Products Zabbix
Zabbix zabbix

Fri, 12 Sep 2025 12:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 12 Sep 2025 10:45:00 +0000

Type Values Removed Values Added
Description Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to them.
Title API hostprototype.get lists data to users with insufficient authorization.
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zabbix

Published:

Updated: 2025-09-15T18:48:19.882Z

Reserved: 2025-02-20T11:40:38.480Z

Link: CVE-2025-27238

cve-icon Vulnrichment

Updated: 2025-09-12T11:54:32.704Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-12T11:15:31.517

Modified: 2025-10-08T14:53:00.293

Link: CVE-2025-27238

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-15T10:43:54Z