Zitadel

Zitadel

27 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Published 11.03.2024 20:15:07
  • Last modified 07.01.2025 15:54:40

Zitadel is an open source identity management system. Zitadel uses a cookie to identify the user agent (browser) and its user sessions. Although the cookie was handled according to best practices, it was accessible on subdomains of the ZITADEL insta...

Exploit
  • EPSS 0.39%
  • Published 30.11.2023 05:15:09
  • Last modified 21.11.2024 08:32:49

ZITADEL is an identity infrastructure system. ZITADEL uses the notification triggering requests Forwarded or X-Forwarded-Host header to build the button link sent in emails for confirming a password reset with the emailed code. If this header is over...

  • EPSS 0.17%
  • Published 08.11.2023 22:15:10
  • Last modified 21.11.2024 08:29:48

ZITADEL provides identity infrastructure. ZITADEL provides administrators the possibility to define a `Lockout Policy` with a maximum amount of failed password check attempts. On every failed password check, the amount of failed checks is compared ag...

  • EPSS 0.53%
  • Published 26.10.2023 15:15:09
  • Last modified 21.11.2024 08:28:08

ZITADEL is an identity infrastructure management system. ZITADEL users can upload their own avatar image using various image types including SVG. SVG can include scripts, such as javascript, which can be executed during rendering. Due to a missing se...

  • EPSS 0.35%
  • Published 10.10.2023 17:15:13
  • Last modified 21.11.2024 08:25:49

ZITADEL provides identity infrastructure. In versions 2.37.2 and prior, ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to guess/enumerate usernames. While this settings was proper...

  • EPSS 0.1%
  • Published 11.01.2023 20:15:08
  • Last modified 21.11.2024 07:44:55

ZITADEL is a combination of Auth0 and Keycloak. RefreshTokens is an OAuth 2.0 feature that allows applications to retrieve new access tokens and refresh the user's session without the need for interacting with a UI. RefreshTokens were not invalidated...

  • EPSS 0.29%
  • Published 31.08.2022 23:15:08
  • Last modified 21.11.2024 07:12:16

ZITADEL combines the ease of Auth0 and the versatility of Keycloak.**Actions**, introduced in ZITADEL **1.42.0** on the API and **1.56.0** for Console, is a feature, where users with role.`ORG_OWNER` are able to create Javascript Code, which is invok...