8.7

CVE-2025-31123

Zitadel Expired JWT Keys Usable for Authorization Grants

Zitadel is open-source identity infrastructure software. A vulnerability existed where expired keys can be used to retrieve tokens. Specifically, ZITADEL fails to properly check the expiration date of the JWT key when used for Authorization Grants. This allows an attacker with an expired key to obtain valid access tokens. This vulnerability does not affect the use of JWT Profile for OAuth 2.0 Client Authentication on the Token and Introspection endpoints, which correctly reject expired keys. This vulnerability is fixed in 2.71.6, 2.70.8, 2.69.9, 2.68.9, 2.67.13, 2.66.16, 2.65.7, 2.64.6, and 2.63.9.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZitadelZitadel Version >= 2.62.0 < 2.63.9
ZitadelZitadel Version >= 2.64.0 < 2.64.6
ZitadelZitadel Version >= 2.65.0 < 2.65.7
ZitadelZitadel Version >= 2.66.0 < 2.66.16
ZitadelZitadel Version >= 2.67.0 < 2.67.13
ZitadelZitadel Version >= 2.68.0 < 2.68.9
ZitadelZitadel Version >= 2.69.0 < 2.69.9
ZitadelZitadel Version >= 2.70.0 < 2.70.8
ZitadelZitadel Version >= 2.71.0 < 2.71.6
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.36% 0.277
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 8.7 2.3 5.8
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
CWE-324 Use of a Key Past its Expiration Date

The product uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.

https://github.com/zitadel/zitadel/commit/315503beabd679f2e6aec0c004f0f9d2f5b53ed3
Patch
https://github.com/zitadel/zitadel/releases/tag/v2.63.9
Release Notes
https://github.com/zitadel/zitadel/releases/tag/v2.64.6
Release Notes
https://github.com/zitadel/zitadel/releases/tag/v2.65.7
Release Notes
https://github.com/zitadel/zitadel/releases/tag/v2.66.16
Release Notes
https://github.com/zitadel/zitadel/releases/tag/v2.67.13
Release Notes
https://github.com/zitadel/zitadel/releases/tag/v2.68.9
Release Notes
https://github.com/zitadel/zitadel/releases/tag/v2.69.9
Release Notes
https://github.com/zitadel/zitadel/releases/tag/v2.70.8
Release Notes
https://github.com/zitadel/zitadel/releases/tag/v2.71.6
Release Notes
https://github.com/zitadel/zitadel/security/advisories/GHSA-h3q7-347g-qwhf
Vendor Advisory