Zitadel

Zitadel

71 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 24.09.2026 17:34:13
  • Zuletzt bearbeitet 28.09.2026 15:17:24

ZITADEL is an open source identity management platform. From 4.0.0 until 4.16.1, ZITADEL Login V2 creates a browser session after password verification and can reuse that session for a later authentication request without verifying a user's enrolled ...

  • EPSS 0.39%
  • Veröffentlicht 24.09.2026 17:31:19
  • Zuletzt bearbeitet 05.10.2026 16:17:16

ZITADEL is an open source identity management platform. From 3.0.0 until 3.4.13 and 4.16.1, ZITADEL Actions V1 enables the goja Node-compatible require() registry without restricting its filesystem source loader. An organization Action author with OR...

  • EPSS 0.23%
  • Veröffentlicht 14.09.2026 21:30:47
  • Zuletzt bearbeitet 16.09.2026 13:42:48

ZITADEL is an open source identity management platform. Prior to version 4.16.0, a bug in how ZITADEL updates permissions when multiple project roles are deleted at the same time can cause some user permissions to be missed. This issue specifically a...

  • EPSS 0.34%
  • Veröffentlicht 29.07.2026 16:50:39
  • Zuletzt bearbeitet 30.07.2026 20:07:01

ZITADEL is an open source identity management platform. From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4.0.0 until 4.15.1, the email and phone self-management API paths in internal/command/user_v2_email.go, internal/command/user_v2_ph...

  • EPSS 0.23%
  • Veröffentlicht 10.07.2026 17:46:25
  • Zuletzt bearbeitet 14.07.2026 14:16:35

ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's OAuth2 Token Exchange endpoint for urn:ietf:params:oauth:grant-type:token-exchange does not verify that the subject token belongs to the requesting client or that requ...

  • EPSS 0.19%
  • Veröffentlicht 10.07.2026 17:37:37
  • Zuletzt bearbeitet 13.07.2026 19:17:23

ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler checks that the local user's email is verified but does not verify that the external IdP confirmed ownership of the same email befor...

  • EPSS 0.23%
  • Veröffentlicht 10.07.2026 17:25:46
  • Zuletzt bearbeitet 10.07.2026 21:16:57

ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL Login V2 OIDC and SAML FailedPrecondition error paths return loginSettings.defaultRedirectUri to router.push without applying the isSafeRedirectUri check, allowing an or...

  • EPSS 0.17%
  • Veröffentlicht 10.07.2026 17:22:46
  • Zuletzt bearbeitet 10.07.2026 19:17:26

ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL is an open source identity management platform. From 3.0.0-rc.1 through 3.4.11 and from 4.0.0-rc.1 through 4.15.1, ZITADEL's external JWT Identity Provider va...

  • EPSS 0.2%
  • Veröffentlicht 10.07.2026 17:21:22
  • Zuletzt bearbeitet 10.07.2026 19:17:26

ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Provider validation in internal/idp/providers/jwt/session.go skips the maximum token age freshness check when an incoming token omits ...

  • EPSS 0.28%
  • Veröffentlicht 10.07.2026 17:19:05
  • Zuletzt bearbeitet 10.07.2026 19:17:25

ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's OAuth2 and OIDC CodeExchange, RefreshToken, and device token flows fail to verify that the requesting client matches the client that initiated the authoriza...