Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36860
HistoryAug 31, 2022 - 3:26 a.m.

Authorization Bypass

2022-08-3103:26:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
vulnerability
authorization bypass
user role
javascript code
user_grant.go
attacker
org owner

EPSS

0.002

Percentile

55.9%

github.com/zitadel/zitadel is vulnerable to authorization bypass. The user role with ORG_OWNER can create javascript code through the user_grant.go and invoked by the system at certain points during the login, allowing an attacker to grant authorizations for projects that belong to other organisations inside the same instance.

EPSS

0.002

Percentile

55.9%

Related for VERACODE:36860