Lack of input validation of the Zendesk subdomain could expose users of the library to Server Side Request Forgery (SSRF).
Validate the provided Zendesk subdomain to be a valid subdomain in:
{
"cwe_ids": [
"CWE-20",
"CWE-918"
],
"github_reviewed": true,
"github_reviewed_at": "2021-04-28T22:29:16Z",
"nvd_published_at": null,
"severity": "CRITICAL"
}