CVE-2024-29891

CVSS 3.1 Score 8.7 of 10 (high)

Details

Published Mar 27, 2024
Updated: Jan 8, 2025
CWE ID 434
CWE ID 79

Summary

CVE-2024-29891 is a vulnerability affecting ZITADEL, where users can upload their own avatar images, and due to a lacking verification process, an attacker could successfully upload HTML code under the guise of an image. In certain circumstances, this could grant unauthorized access to victims' accounts. For this exploit to execute, the victim must directly open the malicious image in their web browser while having an active session in ZITADEL. Notably, this vulnerability only affected Firefox users, as Chrome, Safari, and Edge did not execute the code. This issue has since been resolved in several ZITADEL software versions, including 2.48.3, 2.47.8, 2.46.5, 2.45.5, 2.44.7, 2.43.11, and 2.42.17.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share