PT-2025-23266 · Zitadel · Zitadel
Amit-Laish
·
Published
2025-05-28
·
Updated
2025-06-16
·
CVE-2025-48936
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zitadel versions prior to 2.70.12
Zitadel versions prior to 2.71.10
Zitadel versions prior to 3.2.2
Description
Zitadel is open-source identity infrastructure software. A potential issue exists in the password reset mechanism, where ZITADEL utilizes the
Forwarded or X-Forwarded-Host header from incoming requests to construct the URL for the password reset confirmation link. This link, containing a secret code, is then emailed to the user. If an attacker can manipulate these headers, they could cause ZITadel to generate a password reset link pointing to a malicious domain controlled by the attacker. If the user clicks this manipulated link in the email, the secret reset code embedded in the URL can be captured by the attacker. This captured code could then be used to reset the user's password and gain unauthorized access to their account. This specific attack vector is mitigated for accounts that have Multi-Factor Authentication (MFA) or Passwordless authentication enabled.Recommendations
For versions prior to 2.70.12, update to version 2.70.12 or later.
For versions prior to 2.71.10, update to version 2.71.10 or later.
For versions prior to 3.2.2, update to version 3.2.2 or later.
As a temporary workaround, consider enabling Multi-Factor Authentication (MFA) or Passwordless authentication to mitigate the risk of exploitation.
Exploit
Fix
Open Redirect
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zitadel