Описание
ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Provider validates a token's signature and issuer (iss) but not the audience (aud) claim, allowing a validly signed token from a trusted issuer for another relying party to be accepted by ZITADEL. This issue is fixed in versions 3.4.12 and 4.15.2.
EPSS
Процентиль: 5%
0.00155
Низкий
4.2 Medium
CVSS3
Дефекты
CWE-346
Связанные уязвимости
CVSS3: 4.2
github
3 месяца назад
ZITADEL: Missing Token Audience Validation (`aud`) in JWT IdP Provider
EPSS
Процентиль: 5%
0.00155
Низкий
4.2 Medium
CVSS3
Дефекты
CWE-346