Livio Spring
35 exploits
Active since Jan 2023
ZITADEL < 2.70.10 and 2.71.x < 2.71.9 and 3.0.0-rc.1-3.0.0 - Session Hijacking via IdP Intent Reuse
CVSS 8.0
Zitadel <2.70.12, <2.71.10, <3.2.2 - SSRF
CVSS 8.1
Zitadel < 2.71.15 - Unauthenticated Username Enumeration via Select Account Page
CVSS 5.3
Zitadel < 2.71.18 - Open Redirect via Password Reset Forwarded Header
CVSS 8.1
Zitadel < 2.71.18 - Unauthenticated Online Brute-Force Attack via OTP, TOTP, and Password
CVSS 9.8
Zitadel 2.53.6-2.53.8, 2.54.3, 2.55.0 - Improper Authentication via MFA Bypass
CVSS 9.8
Zitadel 4.0.0-rc.1-4.6.2 - Authenticated Insecure Direct Object Reference via V2Beta API
ZITADEL 4.0.0-4.7.0 - Unauthenticated DOM-Based Cross-Site Scripting via Logout Endpoint
CVSS 8.0
ZITADEL 2.44.0-3.4.4 and 4.0.0-rc.1-4.7.1 - Authenticated Sensitive Information Disclosure via Total User Count
CVSS 4.3
ZITADEL <4.9.1, 3.4.6 - Info Disclosure
CVSS 5.3