Логотип exploitDog
bind:CVE-2024-39683
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-39683

Количество 2

Количество 2

nvd логотип

CVE-2024-39683

больше 1 года назад

ZITADEL is an open-source identity infrastructure tool. ZITADEL provides users the ability to list all user sessions of the current user agent (browser). Starting in version 2.53.0 and prior to versions 2.53.8, 2.54.5, and 2.55.1, due to a missing check, user sessions without that information (e.g. when created though the session service) were incorrectly listed exposing potentially other user's sessions. Versions 2.55.1, 2.54.5, and 2.53.8 contain a fix for the issue. There is no workaround since a patch is already available.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-cvw9-c57h-3397

больше 1 года назад

ZITADEL Vulnerable to Session Information Leakage

CVSS3: 5.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-39683

ZITADEL is an open-source identity infrastructure tool. ZITADEL provides users the ability to list all user sessions of the current user agent (browser). Starting in version 2.53.0 and prior to versions 2.53.8, 2.54.5, and 2.55.1, due to a missing check, user sessions without that information (e.g. when created though the session service) were incorrectly listed exposing potentially other user's sessions. Versions 2.55.1, 2.54.5, and 2.53.8 contain a fix for the issue. There is no workaround since a patch is already available.

CVSS3: 5.7
1%
Низкий
больше 1 года назад
github логотип
GHSA-cvw9-c57h-3397

ZITADEL Vulnerable to Session Information Leakage

CVSS3: 5.7
1%
Низкий
больше 1 года назад

Уязвимостей на страницу