GHSA-q348-f93x-9gx4

    Dashboard / Vulnerabilities / GHSA-q348-f93x-9gx4

    GHSA-q348-f93x-9gx4

    Published: 29 Apr 2021Last Modified: 2 Dec 2024

    Summary: Lack of Input Validation in zendesk_api_client_php for Zendesk Subdomain

    Details: ### Impact Lack of input validation of the Zendesk subdomain could expose users of the library to Server Side Request Forgery (SSRF). ### Resolution Validate the provided Zendesk subdomain to be a valid subdomain in: * getAuthUrl * getAccessToken

    Affected packages

    Package

    Name: zendesk/zendesk_api_client_php

    Purl: pkg:composer/zendesk/zendesk_api_client_php

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.2.11

    Affected versions

    2.0.0-beta
    2.0.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-q348-f93x-9gx4 | CVE-DB