Lucene search

K
githubGitHub Advisory DatabaseGHSA-QR2H-7PWM-H393
HistorySep 19, 2024 - 4:08 p.m.

ZITADEL's Service Users Deactivation not Working

2024-09-1916:08:01
CWE-269
CWE-672
GitHub Advisory Database
github.com
1
zitadel
user account vulnerability
service accounts
unauthorized access
security patches
workarounds
authentication keys
password rotation

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

AI Score

7.2

Confidence

High

Impact

ZITADEL’s user account deactivation mechanism did not work correctly with service accounts. Deactivated service accounts retained the ability to request tokens, which could lead to unauthorized access to applications and resources.

Patches

2.x versions are fixed on >= 2.62.1
2.61.x versions are fixed on >= 2.61.1
2.60.x versions are fixed on >= 2.60.2
2.59.x versions are fixed on >= 2.59.3
2.58.x versions are fixed on >= 2.58.5
2.57.x versions are fixed on >= 2.57.5
2.56.x versions are fixed on >= 2.56.6
2.55.x versions are fixed on >= 2.55.8
2.54.x versions are fixed on >= 2.54.10

Workarounds

Instead of deactivating the service account, consider creating new credentials and replacing the old ones wherever they are used. This effectively prevents the deactivated service account from being utilized.

  • Revoke all existing authentication keys associated with the service account
  • Rotate the service account’s password

Questions

If you have any questions or comments about this advisory, please email us at

[email protected]

Affected configurations

Vulners
Node
zitadelzitadelRange<2.54.10
OR
zitadelzitadelRange2.55.02.55.8
OR
zitadelzitadelRange2.56.02.56.6
OR
zitadelzitadelRange2.57.02.57.5
OR
zitadelzitadelRange2.58.02.58.5
OR
zitadelzitadelRange2.59.02.59.3
OR
zitadelzitadelRange2.60.02.60.2
OR
zitadelzitadelRange2.61.02.61.1
OR
zitadelzitadelRange2.62.02.62.1
VendorProductVersionCPE
zitadelzitadel*cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

AI Score

7.2

Confidence

High

Related for GHSA-QR2H-7PWM-H393