Record summary

CVE-2024-49757 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Due to a missing security check in versions prior to 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7, disabling the "User Registration allowed" option only hid the registration button on the login page. Users could bypass this restriction by directly accessing the registration URL (/ui/login/loginname) and register a user that way. Versions 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 contain a patch. No known workarounds are available.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 25, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List>= 2.63, < 2.63.5affected
>= 2.62, < 2.62.7affected
>= 2.61, < 2.61.3affected
>= 2.60, < 2.60.3affected
>= 2.59, < 2.59.4affected
< 2.58.6affected

github.com/zitadel/zitadel

Browse Go / github.com/zitadel/zitadel
GitHub Advisory2.63.0 to < 2.63.5 · Fixed in 2.63.5affected
2.62.0 to < 2.62.7 · Fixed in 2.62.7affected
2.61.0 to < 2.61.4 · Fixed in 2.61.4affected
2.60.0 to < 2.60.4 · Fixed in 2.60.4affected
2.59.0 to < 2.59.5 · Fixed in 2.59.5affected
Before 2.58.7 · Fixed in 2.58.7affected

Nuclei templates

1
ProjectDiscoveryHIGHZitadel - User Registration BypassCVSS 7.5

The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Due to a missing security check in versions prior to 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7, disabling the "User Registration allowed" option only hid the registration button on the login page. Users could bypass this restriction by directly accessing the registration URL (/ui/login/loginname) and register a user that way. Versions 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 contain a patch. No known workarounds are available.

Impact

Unauthenticated users can bypass the disabled user registration restriction and register accounts.

Remediation

Update Zitadel to version 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, or 2.58.7 or later.

WeaknessesCWE-287
AuthorsSujal Tuladhar
Template tagscvecve2024registerzitadelvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Shodan: title:"Zitadel"

Source: ProjectDiscovery

References

10