ZITADEL Vulnerable to Session Information Leakage
Vulnerability Description
ZITADEL is an open-source identity infrastructure tool. ZITADEL provides users the ability to list all user sessions of the current user agent (browser). Starting in version 2.53.0 and prior to versions 2.53.8, 2.54.5, and 2.55.1, due to a missing check, user sessions without that information (e.g. when created though the session service) were incorrectly listed exposing potentially other user's sessions. Versions 2.55.1, 2.54.5, and 2.53.8 contain a fix for the issue. There is no workaround since a patch is already available.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-39683
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/zitadel/zitadel/security/advisories/GHSA-cvw9-c57h-3397
- https://github.com/zitadel/zitadel/issues/8213
- https://github.com/zitadel/zitadel/pull/8231
- https://github.com/zitadel/zitadel/commit/4a262e42abac2208b02fefaf68ba1a5121649f04
- https://github.com/zitadel/zitadel/commit/c2093ce01507ca8fc811609ff5d391693360c3da
- https://github.com/zitadel/zitadel/commit/d04f208486a418a45b884b9ca8433e5ad9790d73
- https://discord.com/channels/927474939156643850/1254096852937347153
- https://github.com/zitadel/zitadel/releases/tag/v2.53.8
- https://github.com/zitadel/zitadel/releases/tag/v2.54.5
- https://github.com/zitadel/zitadel/releases/tag/v2.55.1
More from zitadel
View All →Affected Vendor
zitadel
View all reports →