CVE-2024-39683

MEDIUM

Zitadel < 2.53.8 - Information Disclosure

Title source: rule
STIX 2.1

Description

ZITADEL is an open-source identity infrastructure tool. ZITADEL provides users the ability to list all user sessions of the current user agent (browser). Starting in version 2.53.0 and prior to versions 2.53.8, 2.54.5, and 2.55.1, due to a missing check, user sessions without that information (e.g. when created though the session service) were incorrectly listed exposing potentially other user's sessions. Versions 2.55.1, 2.54.5, and 2.53.8 contain a fix for the issue. There is no workaround since a patch is already available.

Scores

CVSS v3 5.7
EPSS 0.0061
EPSS Percentile 69.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (3)
zitadel/zitadel 2.55.0 (2 CPE variants)
zitadel/zitadel 2.0.0 - 2.53.8Go
zitadel/zitadel 2.53.0 - 2.53.8
Published Jul 03, 2024
Tracked Since Feb 18, 2026