ZITADEL is an open-source identity infrastructure tool. ZITADEL provides users the ability to list all user sessions of the current user agent (browser). Starting in version 2.53.0 and prior to versions 2.53.8, 2.54.5, and 2.55.1, due to a missing check, user sessions without that information (e.g. when created though the session service) were incorrectly listed exposing potentially other user's sessions. Versions 2.55.1, 2.54.5, and 2.53.8 contain a fix for the issue. There is no workaround since a patch is already available.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Jan 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:zitadel:zitadel:2.55.0:-:*:*:*:*:*:* cpe:2.3:a:zitadel:zitadel:2.55.0:rc1:*:*:*:*:*:* |

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T04:26:15.915Z
Reserved: 2024-06-27T18:44:13.034Z
Link: CVE-2024-39683

Updated: 2024-07-05T18:37:44.593Z

Status : Analyzed
Published: 2024-07-03T20:15:04.840
Modified: 2025-01-08T18:24:07.627
Link: CVE-2024-39683

No data.