CVE-2024-29892
Zitadel
CVE-2024-29892 is a vulnerability in ZITADEL, an open-source authentication management software, where actions could potentially set reserved claims. This claim setting is due to the software's use of Go templates to render the login UI. Although the CVSS score is 4.9 indicating medium severity, the SOCRadar Vulnerability Risk Score (SVRS) of 30 suggests a lower immediate risk, though monitoring is still advised. The flaw could allow unauthorized modification of user claims, potentially leading to privilege escalation or identity spoofing. A protection mechanism has been introduced to prevent changes to claims starting with urn:zitadel:iam
. Patches are available in versions 2.48.3, 2.47.8, 2.46.5, 2.45.5, 2.44.7, 2.43.11, and 2.42.17, mitigating this security risk. Organizations using ZITADEL should upgrade to the latest patched version to ensure proper claim management and prevent potential exploitation. While not immediately critical, remediation is recommended to maintain system integrity.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.