CVE-2024-39683
Starting in version 2.53.0 and prior to versions 2.53.8, 2.54.5, and 2.55.1, due to a missing check, user sessions without that information (e.g. when created though the session service) were incorrectly listed exposing potentially other user's sessions.
Does this matter?
Lower severity and a low EPSS score (0.61%). Track it; it rarely justifies an emergency change on its own.
Description
ZITADEL is an open-source identity infrastructure tool. ZITADEL provides users the ability to list all user sessions of the current user agent (browser). Starting in version 2.53.0 and prior to versions 2.53.8, 2.54.5, and 2.55.1, due to a missing check, user sessions without that information (e.g. when created though the session service) were incorrectly listed exposing potentially other user's sessions. Versions 2.55.1, 2.54.5, and 2.53.8 contain a fix for the issue. There is no workaround since a patch is already available.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.61% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- zitadel/zitadel
- Source
- security-advisories@github.com
References
- https://discord.com/channels/927474939156643850/1254096852937347153Permissions Required, URL Repurposed
- https://github.com/zitadel/zitadel/commit/4a262e42abac2208b02fefaf68ba1a5121649f04Patch
- https://github.com/zitadel/zitadel/commit/c2093ce01507ca8fc811609ff5d391693360c3daPatch
- https://github.com/zitadel/zitadel/commit/d04f208486a418a45b884b9ca8433e5ad9790d73Patch
- https://github.com/zitadel/zitadel/issues/8213Issue Tracking, Release Notes
- https://github.com/zitadel/zitadel/pull/8231Issue Tracking
- https://github.com/zitadel/zitadel/releases/tag/v2.53.8Release Notes
- https://github.com/zitadel/zitadel/releases/tag/v2.54.5Release Notes
- https://github.com/zitadel/zitadel/releases/tag/v2.55.1Release Notes
- https://github.com/zitadel/zitadel/security/advisories/GHSA-cvw9-c57h-3397Vendor Advisory
- https://discord.com/channels/927474939156643850/1254096852937347153Permissions Required, URL Repurposed
- https://github.com/zitadel/zitadel/commit/4a262e42abac2208b02fefaf68ba1a5121649f04Patch
- https://github.com/zitadel/zitadel/commit/c2093ce01507ca8fc811609ff5d391693360c3daPatch
- https://github.com/zitadel/zitadel/commit/d04f208486a418a45b884b9ca8433e5ad9790d73Patch
- https://github.com/zitadel/zitadel/issues/8213Issue Tracking, Release Notes
- https://github.com/zitadel/zitadel/pull/8231Issue Tracking
- https://github.com/zitadel/zitadel/releases/tag/v2.53.8Release Notes
- https://github.com/zitadel/zitadel/releases/tag/v2.54.5Release Notes
- https://github.com/zitadel/zitadel/releases/tag/v2.55.1Release Notes
- https://github.com/zitadel/zitadel/security/advisories/GHSA-cvw9-c57h-3397Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.