CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
AI Score
Confidence
High
ZITADEL is vulnerable to Sensitive Information Disclosure. The vulnerability is due to a missing check that incorrectly lists user sessions without specific information, potentially exposing other users’ sessions.
discord.com/channels/927474939156643850/1254096852937347153
github.com/zitadel/zitadel/commit/4a262e42abac2208b02fefaf68ba1a5121649f04
github.com/zitadel/zitadel/commit/c2093ce01507ca8fc811609ff5d391693360c3da
github.com/zitadel/zitadel/commit/d04f208486a418a45b884b9ca8433e5ad9790d73
github.com/zitadel/zitadel/issues/8213
github.com/zitadel/zitadel/pull/8231
github.com/zitadel/zitadel/releases/tag/v2.53.8
github.com/zitadel/zitadel/releases/tag/v2.54.5
github.com/zitadel/zitadel/releases/tag/v2.55.1
github.com/zitadel/zitadel/security/advisories/GHSA-cvw9-c57h-3397