CVE-2024-29892

CVSS 3.1 Score 4.9 of 10 (medium)

Details

Published Mar 27, 2024
Updated: Jan 8, 2025
CWE ID 863

Summary

CVE-2024-29892 affects ZITADEL, an open-source authentication management software. The vulnerability arises from the use of Go templates in rendering the login UI, which under certain conditions allows an action to set reserved claims managed by ZITAADL. For instance, the claim `urn:zitadel:iam:user:resourceowner:name` could be manipulated. To mitigate this issue, ZITADEL introduced a protection that restricts actions from modifying claims beginning with `urn:zitadel:iam`. This vulnerability has been resolved in versions 2.48.3, 2.47.8, 2.46.5, 2.45.5, 2.44.7, 2.43.11, and 2.42.17.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share