Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3rmw-76m6-4gjc

Опубликовано: 25 окт. 2024
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

User Registration Bypass in Zitadel

Impact

Zitadel allows administrators to disable the user self-registration. Due to a missing security check in versions prior to 2.63.4, disabling the "User Registration allowed" option only hid the registration button on the login page. Users could bypass this restriction by directly accessing the registration URL (/ui/login/loginname) and register a user that way.

Patches

2.x versions are fixed on >= 2.64.0 2.63.x versions are fixed on >= 2.63.5 2.62.x versions are fixed on >= 2.62.7 2.61.x versions are fixed on >= 2.61.4 2.60.x versions are fixed on >= 2.60.4 2.59.x versions are fixed on >= 2.59.5 2.58.x versions are fixed on >= 2.58.7

Workarounds

Updating to the patched version is the recommended solution.

Questions

If you have any questions or comments about this advisory, please email us at security@zitadel.com

Credits

Thanks to @sevensolutions and @evilgensec for disclosing this!

Пакеты

Наименование

github.com/zitadel/zitadel

go
Затронутые версииВерсия исправления

>= 2.63.0, < 2.63.5

2.63.5

Наименование

github.com/zitadel/zitadel

go
Затронутые версииВерсия исправления

>= 2.62.0, < 2.62.7

2.62.7

Наименование

github.com/zitadel/zitadel

go
Затронутые версииВерсия исправления

>= 2.61.0, < 2.61.4

2.61.4

Наименование

github.com/zitadel/zitadel

go
Затронутые версииВерсия исправления

>= 2.60.0, < 2.60.4

2.60.4

Наименование

github.com/zitadel/zitadel

go
Затронутые версииВерсия исправления

>= 2.59.0, < 2.59.5

2.59.5

Наименование

github.com/zitadel/zitadel

go
Затронутые версииВерсия исправления

< 2.58.7

2.58.7

EPSS

Процентиль: 93%
0.10774
Средний

7.5 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Due to a missing security check in versions prior to 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7, disabling the "User Registration allowed" option only hid the registration button on the login page. Users could bypass this restriction by directly accessing the registration URL (/ui/login/loginname) and register a user that way. Versions 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 contain a patch. No known workarounds are available.

suse-cvrf
больше 1 года назад

Security update for govulncheck-vulndb

EPSS

Процентиль: 93%
0.10774
Средний

7.5 High

CVSS3

Дефекты

CWE-287