CVE-2025-31123

CVSS 3.1 Score 8.7 of 10 (high)

Details

Published Mar 31, 2025
Updated: Apr 1, 2025
CWE ID 324

Summary

CVE-2025-31123 is a vulnerability affecting Zitadel, an open-source identity infrastructure software. The issue arises from a failure to verify the expiration date of JSON Web Tokens (JWT) keys used in Authorization Grants. This flaw allows an attacker with an expired key to retrieve valid access tokens, potentially leading to unauthorized access. However, it is important to note that the use of JWT Profile for OAuth 2.0 Client Authentication on the Token and Introspection endpoints remains unaffected, as these endpoints correctly reject expired keys. The vulnerability has been addressed in several Zitadel releases, including 2.71.6, 2.70.8, 2.69.9, 2.68.9, 2.67.13, 2.66.16, 2.65.7, 2.64.6, and 2.63.9.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share