GHSA-q348-f93x-9gx4
Dashboard / Vulnerabilities / GHSA-q348-f93x-9gx4
Summary: Lack of Input Validation in zendesk_api_client_php for Zendesk Subdomain
Details: ### Impact Lack of input validation of the Zendesk subdomain could expose users of the library to Server Side Request Forgery (SSRF). ### Resolution Validate the provided Zendesk subdomain to be a valid subdomain in: * getAuthUrl * getAccessToken
References: https://github.com/zendesk/zendesk_api_client_php/security/advisories/GHSA-q348-f93x-9gx4, https://github.com/zendesk/zendesk_api_client_php/pull/466, https://github.com/zendesk/zendesk_api_client_php/commit/b451b743d9d6d81a9abf7cb86e70ec9c5332123e
Affected packages
Package
Name: zendesk/zendesk_api_client_php
Purl: pkg:composer/zendesk/zendesk_api_client_php
Affected ranges
Type: ECOSYSTEM
Events:
