A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.
| Software | From | Fixed in |
|---|---|---|
| zabbix / zabbix | 6.0.38 | 6.0.41 |
| zabbix / zabbix | 7.0.9 | 7.0.17 |
| zabbix / zabbix | 7.2.3 | 7.2.11 |
| zabbix / zabbix | 7.4.0 | 7.4.0.x |