{"id":"CVE-2021-30492","aliases":[],"url":"https://o3.security/vulnerability/CVE-2021-30492","summary":"Lack of Input Validation in zendesk_api_client_php for Zendesk Subdomain","details":"### Impact\nLack of input validation of the Zendesk subdomain could expose users of the library to Server Side Request Forgery (SSRF).\n\n### Resolution\nValidate the provided Zendesk subdomain to be a valid subdomain in:\n* getAuthUrl\n* getAccessToken","published":"2021-04-29T21:53:06Z","modified":"2024-12-02T05:55:17.026669Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"zendesk/zendesk_api_client_php","fixedVersion":"2.2.11"}],"fix":{"url":"https://github.com/zendesk/zendesk_api_client_php/pull/466","label":"zendesk/zendesk_api_client_php#466"},"references":[{"type":"WEB","url":"https://github.com/zendesk/zendesk_api_client_php/security/advisories/GHSA-q348-f93x-9gx4"},{"type":"WEB","url":"https://github.com/zendesk/zendesk_api_client_php/pull/466"},{"type":"WEB","url":"https://github.com/zendesk/zendesk_api_client_php/commit/b451b743d9d6d81a9abf7cb86e70ec9c5332123e"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-02T05:55:17.026669Z"}}