Livio Spring
20 exploits
Active since Jan 2023
ZITADEL is missing enforcement of organization scopes
CVSS 5.3
Zitadel < 2.16.4 - Insufficient Session Expiration
CVSS 5.9
Zitadel < 2.38.3 - Race Condition
CVSS 7.3
Zitadel < 2.45.7 - Information Disclosure
CVSS 5.3
Zitadel < 2.53.8 - Information Disclosure
CVSS 5.7
Zitadel < 2.53.9 - Information Disclosure
CVSS 5.3
Zitadel < 2.52.3 - XSS
CVSS 4.3
Zitadel - IDOR
CVSS 9.0
Zitadel - Info Disclosure
CVSS 8.7
Zitadel < 2.63.9 - Information Disclosure
CVSS 5.3
ZITADEL <3.0.0-2.70.10 - DoS
CVSS 8.0
Zitadel <2.70.12, <2.71.10, <3.2.2 - SSRF
CVSS 8.1
Zitadel < 2.71.15 - Information Disclosure
CVSS 5.3
Zitadel < 2.71.18 - Open Redirect
CVSS 8.1
Zitadel < 2.71.18 - Brute Force
CVSS 9.8
Zitadel < 2.53.9 - Authentication Bypass
CVSS 9.8
Zitadel < 4.6.3 - IDOR
Zitadel < 4.7.1 - XSS
CVSS 8.0
Zitadel < 2.71.19 - Information Disclosure
CVSS 4.3
ZITADEL <4.9.1, 3.4.6 - Info Disclosure
CVSS 5.3