CVE-2024-29892
Last modified
CVE-2024-29892 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. ZITADEL, open source authentication management software, uses Go templates to render the login UI. Under certain circumstances an action could set reserved claims managed by ZITADEL. EPSS estimates a 0.77% chance of exploitation in the next 30 days.
Description
ZITADEL, open source authentication management software, uses Go templates to render the login UI. Under certain circumstances an action could set reserved claims managed by ZITADEL. For example it would be possible to set the claim `urn:zitadel:iam:user:resourceowner:name`. To compensate for this we introduced a protection that does prevent actions from changing claims that start with `urn:zitadel:iam`. This vulnerability is fixed in 2.48.3, 2.47.8, 2.46.5, 2.45.5, 2.44.7, 2.43.11, and 2.42.17.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zitadel | Zitadel | < 2.42.17 |
| Zitadel | Zitadel | >= 2.43.0, < 2.43.11 |
| Zitadel | Zitadel | >= 2.44.0, < 2.44.7 |
| Zitadel | Zitadel | >= 2.45.0, < 2.45.5 |
| Zitadel | Zitadel | >= 2.46.0, < 2.46.5 |
| Zitadel | Zitadel | >= 2.47.0, < 2.47.8 |
| Zitadel | Zitadel | >= 2.48.0, < 2.48.3 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-29892?
How severe is CVE-2024-29892?
How do I fix CVE-2024-29892?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-29887Serverpod is an app and web server, built for the Flutter an…7.4
- CVE-2024-29888Saleor is an e-commerce platform that serves high-volume com…5.4
- CVE-2024-29889GLPI is a Free Asset and IT Management Software package. Pri…8.1
- CVE-2024-2989A vulnerability, which was classified as critical, has been …8.8
- CVE-2024-29890DataLens is a business intelligence and data visualization s…8.8
- CVE-2024-29891ZITADEL users can upload their own avatar image and various …8.7
- CVE-2024-29893Argo CD is a declarative, GitOps continuous delivery tool fo…6.5
- CVE-2024-29894Cacti provides an operational monitoring and fault managemen…4.7
- CVE-2024-29895Cacti provides an operational monitoring and fault managemen…10
- CVE-2024-29896Astro-Shield is a library to compute the subresource integri…7.5
- CVE-2024-29897CreateWiki is Miraheze's MediaWiki extension for requesting …4.9
- CVE-2024-29898CreateWiki is Miraheze's MediaWiki extension for requesting …6.5
Are you affected by CVE-2024-29892?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
