PT-2024-33664 · Zitadel+1 · Zitadel+1
Prdp1137
·
Published
2024-10-25
·
Updated
2025-08-26
·
CVE-2024-49753
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Zitadel versions prior to 2.64.1
Zitadel versions prior to 2.63.6
Zitadel versions prior to 2.62.8
Zitadel versions prior to 2.61.4
Zitadel versions prior to 2.60.4
Zitadel versions prior to 2.59.5
Zitadel versions prior to 2.58.7
Description:
A flaw in the URL validation mechanism of Zitadel actions allows bypassing restrictions intended to block requests to localhost (127.0.0.1). The
isHostBlocked check can be circumvented by creating a DNS record that resolves to 127.0.0.1, enabling actions to send requests to localhost despite the intended security measures. This potentially allows unauthorized access to unsecured internal endpoints, which may contain sensitive information or functionalities.Recommendations:
Update to version 2.64.1 or later for the 2.x branch.
Update to version 2.63.6 or later for the 2.63.x branch.
Update to version 2.62.8 or later for the 2.62.x branch.
Update to version 2.61.4 or later for the 2.61.x branch.
Update to version 2.60.4 or later for the 2.60.x branch.
Update to version 2.59.5 or later for the 2.59.x branch.
Update to version 2.58.7 or later for the 2.58.x branch.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse
Zitadel