CVE-2024-29891
CVSS 3.1 Score 8.7 of 10 (high)
Details
Summary
CVE-2024-29891 is a vulnerability affecting ZITADEL, where users can upload their own avatar images, and due to a lacking verification process, an attacker could successfully upload HTML code under the guise of an image. In certain circumstances, this could grant unauthorized access to victims' accounts. For this exploit to execute, the victim must directly open the malicious image in their web browser while having an active session in ZITADEL. Notably, this vulnerability only affected Firefox users, as Chrome, Safari, and Edge did not execute the code. This issue has since been resolved in several ZITADEL software versions, including 2.48.3, 2.47.8, 2.46.5, 2.45.5, 2.44.7, 2.43.11, and 2.42.17.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.