- EPSS -
- Veröffentlicht 09.12.2025 22:38:44
- Zuletzt bearbeitet 09.12.2025 23:15:59
ZITADEL is an open-source identity infrastructure tool. Versions 4.0.0-rc.1 through 4.7.0 are vulnerable to DOM-Based XSS through the Zitadel V2 logout endpoint. The /logout endpoint insecurely routes to a value that is supplied in the post_logout_re...
CVE-2025-67494
- EPSS -
- Veröffentlicht 09.12.2025 22:16:16
- Zuletzt bearbeitet 09.12.2025 22:16:16
ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, full-read SSRF vulnerability. The ZITADEL Login UI (V2) treats the x-zitadel-forward-host header as a trusted fallback for all depl...
CVE-2025-64717
- EPSS 0.31%
- Veröffentlicht 13.11.2025 15:30:51
- Zuletzt bearbeitet 04.12.2025 14:39:53
ZITADEL is an open source identity management platform. Starting in version 2.50.0 and prior to versions 2.71.19, 3.4.4, and 4.6.6, a vulnerability in ZITADEL's federation process allowed auto-linking users from external identity providers to existin...
CVE-2025-64431
- EPSS 0.05%
- Veröffentlicht 07.11.2025 18:09:25
- Zuletzt bearbeitet 12.11.2025 16:20:22
Zitadel is an open source identity management platform. Versions 4.0.0-rc.1 through 4.6.2 are vulnerable to secure Direct Object Reference (IDOR) attacks through its V2Beta API, allowing authenticated users with specific administrator roles within on...
CVE-2025-64103
- EPSS 0.11%
- Veröffentlicht 29.10.2025 18:43:46
- Zuletzt bearbeitet 04.11.2025 13:17:27
Starting from 2.53.6, 2.54.3, and 2.55.0, Zitadel only required multi factor authentication in case the login policy has either enabled requireMFA or requireMFAForLocalUsers. If a user has set up MFA without this requirement, Zitadel would consider s...
CVE-2025-64102
- EPSS 0.05%
- Veröffentlicht 29.10.2025 18:36:15
- Zuletzt bearbeitet 04.11.2025 13:18:57
Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, an attacker can perform an online brute-force attack on OTP, TOTP, and passwords. While Zitadel allows preventing online brute force attacks in scenarios lik...
CVE-2025-64101
- EPSS 0.1%
- Veröffentlicht 29.10.2025 18:30:14
- Zuletzt bearbeitet 04.11.2025 13:20:04
Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, a potential vulnerability exists in ZITADEL's password reset mechanism. ZITADEL utilizes the Forwarded or X-Forwarded-Host header from incoming requests to c...
CVE-2025-57770
- EPSS 0.07%
- Veröffentlicht 22.08.2025 16:50:35
- Zuletzt bearbeitet 27.08.2025 19:12:57
The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Versions 4.0.0 to 4.0.2, 3.0.0 to 3.3.6, and all versions prior to 2.71.15 are vulnerable to a username enumeration issue in the log...
CVE-2025-53895
- EPSS 0.09%
- Veröffentlicht 15.07.2025 16:39:00
- Zuletzt bearbeitet 26.08.2025 17:52:08
ZITADEL is an open source identity management system. Starting in version 2.53.0 and prior to versions 4.0.0-rc.2, 3.3.2, 2.71.13, and 2.70.14, vulnerability in ZITADEL's session management API allows any authenticated user to update a session if the...
CVE-2025-48936
- EPSS 0.06%
- Veröffentlicht 30.05.2025 06:30:57
- Zuletzt bearbeitet 04.06.2025 18:31:41
Zitadel is open-source identity infrastructure software. Prior to versions 2.70.12, 2.71.10, and 3.2.2, a potential vulnerability exists in the password reset mechanism. ZITADEL utilizes the Forwarded or X-Forwarded-Host header from incoming requests...