PT-2024-22608 · Zitadel · Zitadel

Daniel Philipp

+1

·

Published

2024-03-18

·

Updated

2025-01-08

·

CVE-2024-28855

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ZITADEL versions prior to 2.47.3 ZITADEL versions prior to 2.46.1 ZITADEL versions prior to 2.45.1 ZITADEL versions prior to 2.44.3 ZITADEL versions prior to 2.43.9 ZITADEL versions prior to 2.42.15 ZITADEL versions prior to 2.41.15
Description ZITADEL, open source authentication management software, uses Go templates to render the login UI. Due to the improper use of the text/template instead of the html/template package, the Login UI did not sanitize input parameters. An attacker could create a malicious link, where he injected code which would be rendered as part of the login screen. While it was possible to inject HTML including JavaScript, the execution of such scripts would be prevented by the Content Security Policy.
Recommendations Update to version 2.47.3 or later for 2.x versions. Update to version 2.46.1 or later for 2.46.x versions. Update to version 2.45.1 or later for 2.45.x versions. Update to version 2.44.3 or later for 2.44.x versions. Update to version 2.43.9 or later for 2.43.x versions. Update to version 2.42.15 or later for 2.42.x versions. Update to version 2.41.15 or later for 2.41.x versions.

Exploit

Fix

RCE

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-28855
GHSA-HFRG-4JWR-JFPJ
GO-2024-2655

Affected Products

Zitadel