PT-2023-18543 · Zitadel · Zitadel
Livio-Aco
·
Publicado
2023-01-11
·
Atualizado
2023-01-24
·
CVE-2023-22492
CVSS v3.1
5.9
Média
| Vetor | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
ZITADEL versions prior to 2.16.4
ZITADEL versions prior to 2.17.3
Description
ZITADEL is a combination of Auth0 and Keycloak. RefreshTokens is an OAuth 2.0 feature that allows applications to retrieve new access tokens and refresh the user's session without the need for interacting with a UI. RefreshTokens were not invalidated when a user was locked or deactivated. The deactivated or locked user was able to obtain a valid access token only through a refresh token grant. When the locked or deactivated user’s session was already terminated (“logged out”) then it was not possible to create a new session. Renewal of access token through a refresh token grant is limited to the configured amount of time (
RefreshTokenExpiration).Recommendations
For versions prior to 2.16.4, update to version 2.16.4 or later.
For versions prior to 2.17.3, update to version 2.17.3 or later.
As a temporary workaround, ensure the
RefreshTokenExpiration in the OIDC settings of your instance is set according to your security requirements.Exploit
Correção
Insufficient Session Expiration
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Zitadel