Livio Spring
35 exploits
Active since Jan 2023
ZITADEL 2.0.0-2.16.3 and 2.17.0-2.17.2 - Insufficient Session Expiration via Refresh Token
CVSS 5.9
Zitadel 2.52.0-2.52.2 - Cross-Site Scripting via Username Field
CVSS 4.3
Zitadel 2.53.0-2.53.8 - Username Enumeration via Error Message Discrepancy
CVSS 5.3
Zitadel 2.52.0-2.52.2 - Cross-Site Scripting via Username Field
CVSS 4.3
Zitadel 2.53.0-2.53.8 - Username Enumeration via Error Message Discrepancy
CVSS 5.3
Zitadel 2.52.0-2.52.2 - Cross-Site Scripting via Username Field
CVSS 4.3
ZITADEL 2.53.0-2.53.7 - Unauthorized Exposure of User Sessions via Session Listing
CVSS 5.7
Zitadel 2.53.0-2.53.8 - Username Enumeration via Error Message Discrepancy
CVSS 5.3
Zitadel 2.52.0-2.52.2 - Cross-Site Scripting via Username Field
CVSS 4.3
ZITADEL 2.53.0-2.53.7 - Unauthorized Exposure of User Sessions via Session Listing
CVSS 5.7
Zitadel 2.53.0-2.53.8 - Username Enumeration via Error Message Discrepancy
CVSS 5.3
Zitadel 2.52.0-2.52.2 - Cross-Site Scripting via Username Field
CVSS 4.3
Zitadel 2.53.0-2.53.8 - Username Enumeration via Error Message Discrepancy
CVSS 5.3
Zitadel 2.52.0-2.52.2 - Cross-Site Scripting via Username Field
CVSS 4.3
ZITADEL <4.9.1, 3.4.6 - Info Disclosure
CVSS 5.3
ZITADEL is missing enforcement of organization scopes
CVSS 5.3
ZITADEL 2.0.0-2.16.3 and 2.17.0-2.17.2 - Insufficient Session Expiration via Refresh Token
CVSS 5.9
ZITADEL < 2.38.3 and 2.39.0-2.40.5 - Race Condition in Password Check Lockout Policy
CVSS 7.3
zitadel < 2.45.7 and 2.50.0-2.50.3 - Unauthorized Sensitive Information Exposure via Database Connection Error
CVSS 5.3
ZITADEL 2.53.0-2.53.7 - Unauthorized Exposure of User Sessions via Session Listing
CVSS 5.7
Zitadel 2.53.0-2.53.8 - Username Enumeration via Error Message Discrepancy
CVSS 5.3
Zitadel 2.52.0-2.52.2 - Cross-Site Scripting via Username Field
CVSS 4.3
Zitadel Admin API - LDAP Configuration Insecure Direct Object Reference
CVSS 9.0
Zitadel 2.62.0-2.63.8 - Use of Expired JWT Key for Authorization Grants
CVSS 8.7
zitadel < 2.63.9 - Username Enumeration via Normalization Bypass
CVSS 5.3