CVE-2024-29892
CVSS 3.1 Score 4.9 of 10 (medium)
Details
Summary
CVE-2024-29892 affects ZITADEL, an open-source authentication management software. The vulnerability arises from the use of Go templates in rendering the login UI, which under certain conditions allows an action to set reserved claims managed by ZITAADL. For instance, the claim `urn:zitadel:iam:user:resourceowner:name` could be manipulated. To mitigate this issue, ZITADEL introduced a protection that restricts actions from modifying claims beginning with `urn:zitadel:iam`. This vulnerability has been resolved in versions 2.48.3, 2.47.8, 2.46.5, 2.45.5, 2.44.7, 2.43.11, and 2.42.17.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.