ZITADEL is an open-source identity infrastructure tool. ZITADEL provides users the ability to list all user sessions of the current user agent (browser). Starting in version 2.53.0 and prior to versions 2.53.8, 2.54.5, and 2.55.1, due to a missing check, user sessions without that information (e.g. when created though the session service) were incorrectly listed exposing potentially other user's sessions. Versions 2.55.1, 2.54.5, and 2.53.8 contain a fix for the issue. There is no workaround since a patch is already available.
References
Configurations
Configuration 1 (hide)
|
History
08 Jan 2025, 18:24
Type | Values Removed | Values Added |
---|---|---|
First Time |
Zitadel
Zitadel zitadel |
|
CPE | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* cpe:2.3:a:zitadel:zitadel:2.55.0:-:*:*:*:*:*:* cpe:2.3:a:zitadel:zitadel:2.55.0:rc1:*:*:*:*:*:* |
|
CWE | NVD-CWE-noinfo | |
References | () https://discord.com/channels/927474939156643850/1254096852937347153 - Permissions Required, URL Repurposed | |
References | () https://github.com/zitadel/zitadel/commit/4a262e42abac2208b02fefaf68ba1a5121649f04 - Patch | |
References | () https://github.com/zitadel/zitadel/commit/c2093ce01507ca8fc811609ff5d391693360c3da - Patch | |
References | () https://github.com/zitadel/zitadel/commit/d04f208486a418a45b884b9ca8433e5ad9790d73 - Patch | |
References | () https://github.com/zitadel/zitadel/issues/8213 - Release Notes | |
References | () https://github.com/zitadel/zitadel/pull/8231 - Issue Tracking | |
References | () https://github.com/zitadel/zitadel/releases/tag/v2.53.8 - Release Notes | |
References | () https://github.com/zitadel/zitadel/releases/tag/v2.54.5 - Release Notes | |
References | () https://github.com/zitadel/zitadel/releases/tag/v2.55.1 - Release Notes | |
References | () https://github.com/zitadel/zitadel/security/advisories/GHSA-cvw9-c57h-3397 - Vendor Advisory |
21 Nov 2024, 09:28
Type | Values Removed | Values Added |
---|---|---|
References | () https://discord.com/channels/927474939156643850/1254096852937347153 - | |
References | () https://github.com/zitadel/zitadel/commit/4a262e42abac2208b02fefaf68ba1a5121649f04 - | |
References | () https://github.com/zitadel/zitadel/commit/c2093ce01507ca8fc811609ff5d391693360c3da - | |
References | () https://github.com/zitadel/zitadel/commit/d04f208486a418a45b884b9ca8433e5ad9790d73 - | |
References | () https://github.com/zitadel/zitadel/issues/8213 - | |
References | () https://github.com/zitadel/zitadel/pull/8231 - | |
References | () https://github.com/zitadel/zitadel/releases/tag/v2.53.8 - | |
References | () https://github.com/zitadel/zitadel/releases/tag/v2.54.5 - | |
References | () https://github.com/zitadel/zitadel/releases/tag/v2.55.1 - | |
References | () https://github.com/zitadel/zitadel/security/advisories/GHSA-cvw9-c57h-3397 - |
05 Jul 2024, 12:55
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
03 Jul 2024, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-03 20:15
Updated : 2025-01-08 18:24
NVD link : CVE-2024-39683
Mitre link : CVE-2024-39683
CVE.ORG link : CVE-2024-39683
JSON object : View
Products Affected
zitadel
- zitadel
CWE