Логотип exploitDog
bind:CVE-2025-64717
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-64717

Количество 3

Количество 3

nvd логотип

CVE-2025-64717

3 месяца назад

ZITADEL is an open source identity management platform. Starting in version 2.50.0 and prior to versions 2.71.19, 3.4.4, and 4.6.6, a vulnerability in ZITADEL's federation process allowed auto-linking users from external identity providers to existing users in ZITADEL even if the corresponding IdP was not active or if the organization did not allow federated authentication. This vulnerability stems from the platform's failure to correctly check or enforce an organization's specific security settings during the authentication flow. An Organization Administrator can explicitly disable an IdP or disallow federation, but this setting was not being honored during the auto-linking process. This allowed an unauthenticated attacker to initiate a login using an IdP that should have been disabled for that organization. The platform would incorrectly validate the login and, based on a matching criteria, link the attacker's external identity to an existing internal user account. This may result in

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-j4g7-v4m4-77px

3 месяца назад

ZITADEL is vulnerable to Account Takeover with deactivated Instance IdP

EPSS: Низкий
fstec логотип

BDU:2026-00127

3 месяца назад

Уязвимость программной платформы для управления идентификационными данными ZITADEL, связанная с недостатками процедуры аутентификации, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-64717

ZITADEL is an open source identity management platform. Starting in version 2.50.0 and prior to versions 2.71.19, 3.4.4, and 4.6.6, a vulnerability in ZITADEL's federation process allowed auto-linking users from external identity providers to existing users in ZITADEL even if the corresponding IdP was not active or if the organization did not allow federated authentication. This vulnerability stems from the platform's failure to correctly check or enforce an organization's specific security settings during the authentication flow. An Organization Administrator can explicitly disable an IdP or disallow federation, but this setting was not being honored during the auto-linking process. This allowed an unauthenticated attacker to initiate a login using an IdP that should have been disabled for that organization. The platform would incorrectly validate the login and, based on a matching criteria, link the attacker's external identity to an existing internal user account. This may result in

CVSS3: 9.8
0%
Низкий
3 месяца назад
github логотип
GHSA-j4g7-v4m4-77px

ZITADEL is vulnerable to Account Takeover with deactivated Instance IdP

0%
Низкий
3 месяца назад
fstec логотип
BDU:2026-00127

Уязвимость программной платформы для управления идентификационными данными ZITADEL, связанная с недостатками процедуры аутентификации, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

CVSS3: 6.5
0%
Низкий
3 месяца назад

Уязвимостей на страницу