CVE-2024-47000
- EPSS 0.12%
- Veröffentlicht 20.09.2024 00:15:03
- Zuletzt bearbeitet 24.09.2024 20:25:30
Zitadel is an open source identity management platform. ZITADEL's user account deactivation mechanism did not work correctly with service accounts. Deactivated service accounts retained the ability to request tokens, which could lead to unauthorized ...
CVE-2024-46999
- EPSS 0.11%
- Veröffentlicht 20.09.2024 00:15:03
- Zuletzt bearbeitet 24.09.2024 20:20:39
Zitadel is an open source identity management platform. ZITADEL's user grants deactivation mechanism did not work correctly. Deactivated user grants were still provided in token, which could lead to unauthorized access to applications and resources. ...
CVE-2024-41952
- EPSS 0.49%
- Veröffentlicht 31.07.2024 17:15:10
- Zuletzt bearbeitet 08.01.2025 18:27:21
Zitadel is an open source identity management system. ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to guess/enumerate usernames. If enabled, ZITADEL will show the password promp...
CVE-2024-41953
- EPSS 1.93%
- Veröffentlicht 31.07.2024 17:15:10
- Zuletzt bearbeitet 08.01.2025 18:29:25
Zitadel is an open source identity management system. ZITADEL uses HTML for emails and renders certain information such as usernames dynamically. That information can be entered by users or administrators. Due to a missing output sanitization, these ...
CVE-2024-39683
- EPSS 0.45%
- Veröffentlicht 03.07.2024 20:15:04
- Zuletzt bearbeitet 08.01.2025 18:24:07
ZITADEL is an open-source identity infrastructure tool. ZITADEL provides users the ability to list all user sessions of the current user agent (browser). Starting in version 2.53.0 and prior to versions 2.53.8, 2.54.5, and 2.55.1, due to a missing ch...
CVE-2024-32967
- EPSS 0.39%
- Veröffentlicht 01.05.2024 07:15:40
- Zuletzt bearbeitet 08.01.2025 18:30:33
Zitadel is an open source identity management system. In case ZITADEL could not connect to the database, connection information including db name, username and db host name could be returned to the user. This has been addressed in all supported relea...
CVE-2024-32868
- EPSS 0.14%
- Veröffentlicht 26.04.2024 00:15:08
- Zuletzt bearbeitet 08.01.2025 18:21:50
ZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SMS and Email. While ZITADEL already gives administrators the option to define a `Lockout Policy` with a maximum amount of failed pa...
CVE-2024-29892
- EPSS 0.17%
- Veröffentlicht 27.03.2024 20:15:08
- Zuletzt bearbeitet 08.01.2025 18:20:34
ZITADEL, open source authentication management software, uses Go templates to render the login UI. Under certain circumstances an action could set reserved claims managed by ZITADEL. For example it would be possible to set the claim `urn:zitadel:iam:...
CVE-2024-29891
- EPSS 0.83%
- Veröffentlicht 27.03.2024 20:15:07
- Zuletzt bearbeitet 08.01.2025 18:16:59
ZITADEL users can upload their own avatar image and various image types are allowed. Due to a missing check, an attacker could upload HTML and pretend it is an image to gain access to the victim's account in certain scenarios. A possible victim would...
CVE-2024-28855
- EPSS 1.19%
- Veröffentlicht 18.03.2024 22:15:08
- Zuletzt bearbeitet 08.01.2025 18:14:28
ZITADEL, open source authentication management software, uses Go templates to render the login UI. Due to a improper use of the `text/template` instead of the `html/template` package, the Login UI did not sanitize input parameters prior to versions 2...