PT-2024-33664 · Zitadel+1 · Zitadel+1

Prdp1137

·

Published

2024-10-25

·

Updated

2025-08-26

·

CVE-2024-49753

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Zitadel versions prior to 2.64.1 Zitadel versions prior to 2.63.6 Zitadel versions prior to 2.62.8 Zitadel versions prior to 2.61.4 Zitadel versions prior to 2.60.4 Zitadel versions prior to 2.59.5 Zitadel versions prior to 2.58.7
Description: A flaw in the URL validation mechanism of Zitadel actions allows bypassing restrictions intended to block requests to localhost (127.0.0.1). The isHostBlocked check can be circumvented by creating a DNS record that resolves to 127.0.0.1, enabling actions to send requests to localhost despite the intended security measures. This potentially allows unauthorized access to unsecured internal endpoints, which may contain sensitive information or functionalities.
Recommendations: Update to version 2.64.1 or later for the 2.x branch. Update to version 2.63.6 or later for the 2.63.x branch. Update to version 2.62.8 or later for the 2.62.x branch. Update to version 2.61.4 or later for the 2.61.x branch. Update to version 2.60.4 or later for the 2.60.x branch. Update to version 2.59.5 or later for the 2.59.x branch. Update to version 2.58.7 or later for the 2.58.x branch.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-49753
GHSA-6CF5-W9H3-4RQV
GO-2024-3216
OPENSUSE-SU-2024:0350-1
OPENSUSE-SU-2024:14447-1
OPENSUSE-SU-2024_3911-1
SUSE-SU-2024:3911-1

Affected Products

Suse
Zitadel