Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:46075
HistoryMar 29, 2024 - 8:08 a.m.

Incorrect Authorization

2024-03-2908:08:02
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7
zitadel
vulnerability
authorization
protection
mechanism
software

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N

AI Score

6.7

Confidence

High

EPSS

0

Percentile

13.0%

ZITADEL is vulnerable to Incorrect Authorization. The vulnerability is due to certain actions being able to set reserved claims managed by ZITADEL, such as urn:zitadel:iam:user:resourceowner:name. To address this, a protection mechanism has been introduced to prevent actions from altering claims starting with urn:zitadel:iam.

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N

AI Score

6.7

Confidence

High

EPSS

0

Percentile

13.0%