CVE-2024-41953 - CVE House
Back to Database
Status published Medium CVE-2024-41953

Zitadel improperly sanitizes HTML in emails and Console UI

Vulnerability Description

Zitadel is an open source identity management system. ZITADEL uses HTML for emails and renders certain information such as usernames dynamically. That information can be entered by users or administrators. Due to a missing output sanitization, these emails could include malicious code. This may potentially lead to a threat where an attacker, without privileges, could send out altered notifications that are part of the registration processes. An attacker could create a malicious link, where the injected code would be rendered as part of the email. On the user's detail page, the username was also not sanitized and would also render HTML, giving an attacker the same vulnerability. While it was possible to inject HTML including javascript, the execution of such scripts would be prevented by most email clients and the Content Security Policy in Console UI. This vulnerability is fixed in 2.58.1, 2.57.1, 2.56.2, 2.55.5, 2.54.8 2.53.9, and 2.52.3.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-41953

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

zitadel
Vulnerable Versions:
>= 2.52.0, < 2.52.3, >= 2.53.0, < 2.53.9, >= 2.54.0, < 2.54.8, >= 2.55.0, < 2.55.5, >= 2.56.0, < 2.56.2, >= 2.57.0, < 2.57.1, >= 2.58.0, < 2.58.1

Timeline

Official Publish: July 31st, 2024
Last Modified: August 1st, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Weaknesses (CWE)