CVE-2024-29891
Last modified
CVE-2024-29891 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. ZITADEL users can upload their own avatar image and various image types are allowed. Due to a missing check, an attacker could upload HTML and pretend it is an image to gain access to the victim's account in certain scenarios. EPSS estimates a 0.76% chance of exploitation in the next 30 days.
Description
ZITADEL users can upload their own avatar image and various image types are allowed. Due to a missing check, an attacker could upload HTML and pretend it is an image to gain access to the victim's account in certain scenarios. A possible victim would need to directly open the supposed image in the browser, where a session in ZITADEL needs to be active for this exploit to work. The exploit could only be reproduced if the victim was using Firefox. Chrome, Safari as well as Edge did not execute the code. This vulnerability is fixed in 2.48.3, 2.47.8, 2.46.5, 2.45.5, 2.44.7, 2.43.11, and 2.42.17.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zitadel | Zitadel | < 2.42.17 |
| Zitadel | Zitadel | >= 2.43.0, < 2.43.11 |
| Zitadel | Zitadel | >= 2.44.0, < 2.44.7 |
| Zitadel | Zitadel | >= 2.45.0, < 2.45.5 |
| Zitadel | Zitadel | >= 2.46.0, < 2.46.5 |
| Zitadel | Zitadel | >= 2.47.0, < 2.47.8 |
| Zitadel | Zitadel | >= 2.48.0, < 2.48.3 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-29891?
How severe is CVE-2024-29891?
How do I fix CVE-2024-29891?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-29886Serverpod is an app and web server, built for the Flutter an…5.3
- CVE-2024-29887Serverpod is an app and web server, built for the Flutter an…7.4
- CVE-2024-29888Saleor is an e-commerce platform that serves high-volume com…5.4
- CVE-2024-29889GLPI is a Free Asset and IT Management Software package. Pri…8.1
- CVE-2024-2989A vulnerability, which was classified as critical, has been …8.8
- CVE-2024-29890DataLens is a business intelligence and data visualization s…8.8
- CVE-2024-29892ZITADEL, open source authentication management software, use…4.9
- CVE-2024-29893Argo CD is a declarative, GitOps continuous delivery tool fo…6.5
- CVE-2024-29894Cacti provides an operational monitoring and fault managemen…4.7
- CVE-2024-29895Cacti provides an operational monitoring and fault managemen…10
- CVE-2024-29896Astro-Shield is a library to compute the subresource integri…7.5
- CVE-2024-29897CreateWiki is Miraheze's MediaWiki extension for requesting …4.9
Are you affected by CVE-2024-29891?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
