Lucene search

K
cveGitHub_MCVE-2023-47111
HistoryNov 08, 2023 - 10:15 p.m.

CVE-2023-47111

2023-11-0822:15:10
CWE-362
GitHub_M
web.nvd.nist.gov
36
zitadel
identity infrastructure
lockout policy
password checks
authentication
vulnerability
patch
cve-2023-47111

CVSS3

7.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

AI Score

4.2

Confidence

High

EPSS

0.001

Percentile

20.4%

ZITADEL provides identity infrastructure. ZITADEL provides administrators the possibility to define a Lockout Policy with a maximum amount of failed password check attempts. On every failed password check, the amount of failed checks is compared against the configured maximum. Exceeding the limit, will lock the user and prevent further authentication. In the affected implementation it was possible for an attacker to start multiple parallel password checks, giving him the possibility to try out more combinations than configured in the Lockout Policy. This vulnerability has been patched in versions 2.40.5 and 2.38.3.

Affected configurations

Nvd
Vulners
Node
zitadelzitadelRange<2.38.3
OR
zitadelzitadelRange2.39.02.40.5
VendorProductVersionCPE
zitadelzitadel*cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "zitadel",
    "product": "zitadel",
    "versions": [
      {
        "version": ">= 2.39.0, < 2.40.5",
        "status": "affected"
      },
      {
        "version": "< 2.38.3",
        "status": "affected"
      }
    ]
  }
]

CVSS3

7.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

AI Score

4.2

Confidence

High

EPSS

0.001

Percentile

20.4%