CVE-2024-29892

MEDIUM

ZITADEL <2.48.3 - Command Injection

Title source: llm
STIX 2.1

Description

ZITADEL, open source authentication management software, uses Go templates to render the login UI. Under certain circumstances an action could set reserved claims managed by ZITADEL. For example it would be possible to set the claim `urn:zitadel:iam:user:resourceowner:name`. To compensate for this we introduced a protection that does prevent actions from changing claims that start with `urn:zitadel:iam`. This vulnerability is fixed in 2.48.3, 2.47.8, 2.46.5, 2.45.5, 2.44.7, 2.43.11, and 2.42.17.

Scores

CVSS v3 6.1
EPSS 0.0077
EPSS Percentile 50.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-863
Status published
Products (2)
zitadel/zitadel < 2.42.17
zitadel/zitadel 0 - 2.42.17Go
Published Mar 27, 2024
Tracked Since Feb 18, 2026