Zitadel

Zitadel

71 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.59%
  • Veröffentlicht 04.03.2025 17:15:20
  • Zuletzt bearbeitet 26.08.2025 17:15:22

The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. ZITADEL's Admin API contains Insecure Direct Object Reference (IDOR) vulnerabilities that allow authenticated users, without specifi...

  • EPSS 2.52%
  • Veröffentlicht 25.10.2024 15:15:18
  • Zuletzt bearbeitet 26.08.2025 16:31:17

The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Due to a missing security check in versions prior to 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7, disabling the "User...

Exploit
  • EPSS 0.65%
  • Veröffentlicht 25.10.2024 14:15:12
  • Zuletzt bearbeitet 26.08.2025 16:28:04

Zitadel is open-source identity infrastructure software. Versions prior to 2.64.1, 2.63.6, 2.62.8, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 have a flaw in the URL validation mechanism of Zitadel actions allows bypassing restrictions intended to block reque...

  • EPSS 0.36%
  • Veröffentlicht 20.09.2024 00:15:03
  • Zuletzt bearbeitet 25.09.2024 16:43:47

Zitadel is an open source identity management platform. In Zitadel, even after an organization is deactivated, associated projects, respectively their applications remain active. Users across other organizations can still log in and access through th...

  • EPSS 0.41%
  • Veröffentlicht 20.09.2024 00:15:03
  • Zuletzt bearbeitet 24.09.2024 20:25:30

Zitadel is an open source identity management platform. ZITADEL's user account deactivation mechanism did not work correctly with service accounts. Deactivated service accounts retained the ability to request tokens, which could lead to unauthorized ...

  • EPSS 0.33%
  • Veröffentlicht 20.09.2024 00:15:03
  • Zuletzt bearbeitet 24.09.2024 20:20:39

Zitadel is an open source identity management platform. ZITADEL's user grants deactivation mechanism did not work correctly. Deactivated user grants were still provided in token, which could lead to unauthorized access to applications and resources. ...

  • EPSS 0.65%
  • Veröffentlicht 31.07.2024 17:15:10
  • Zuletzt bearbeitet 08.01.2025 18:29:25

Zitadel is an open source identity management system. ZITADEL uses HTML for emails and renders certain information such as usernames dynamically. That information can be entered by users or administrators. Due to a missing output sanitization, these ...

  • EPSS 0.63%
  • Veröffentlicht 31.07.2024 17:15:10
  • Zuletzt bearbeitet 08.01.2025 18:27:21

Zitadel is an open source identity management system. ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to guess/enumerate usernames. If enabled, ZITADEL will show the password promp...

  • EPSS 0.61%
  • Veröffentlicht 03.07.2024 20:15:04
  • Zuletzt bearbeitet 08.01.2025 18:24:07

ZITADEL is an open-source identity infrastructure tool. ZITADEL provides users the ability to list all user sessions of the current user agent (browser). Starting in version 2.53.0 and prior to versions 2.53.8, 2.54.5, and 2.55.1, due to a missing ch...

  • EPSS 0.64%
  • Veröffentlicht 01.05.2024 07:15:40
  • Zuletzt bearbeitet 08.01.2025 18:30:33

Zitadel is an open source identity management system. In case ZITADEL could not connect to the database, connection information including db name, username and db host name could be returned to the user. This has been addressed in all supported relea...