Описание
ZITADEL is an open source identity management platform. From version 4.0.0 to 4.12.0, a vulnerability in Zitadel's login V2 UI allowed users to bypass login behavior and security policies and self-register new accounts or sign in using password even if corresponding options were disabled in their organizaton. This issue has been patched in version 4.12.1.
Ссылки
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 4.0.0 (включая) до 4.12.1 (исключая)
cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*
EPSS
Процентиль: 24%
0.00312
Низкий
8.2 High
CVSS3
Дефекты
CWE-287
Связанные уязвимости
CVSS3: 8.2
github
5 месяцев назад
ZITADEL: Login V2 UI Policy Bypass Allows Unauthorized Self-Registration and Authentication
EPSS
Процентиль: 24%
0.00312
Низкий
8.2 High
CVSS3
Дефекты
CWE-287