ZITADEL 易受会话信息泄露 (CVE-2024-39683)

admin 2024-07-09 08:28:59 Ali_nvd 来源:ZONE.CI 全球网 0 阅读模式
ZITADEL 易受会话信息泄露 (CVE-2024-39683)

CVE编号

CVE-2024-39683

利用情况

暂无

补丁情况

N/A

披露时间

2024-07-04
漏洞描述
ZITADEL is an open-source identity infrastructure tool. ZITADEL provides users the ability to list all user sessions of the current user agent (browser). Starting in version 2.53.0 and prior to versions 2.53.8, 2.54.5, and 2.55.1, due to a missing check, user sessions without that information (e.g. when created though the session service) were incorrectly listed exposing potentially other user's sessions. Versions 2.55.1, 2.54.5, and 2.53.8 contain a fix for the issue. There is no workaround since a patch is already available.
解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接
https://discord.com/channels/927474939156643850/1254096852937347153
https://github.com/zitadel/zitadel/commit/4a262e42abac2208b02fefaf68ba1a5121649f04
https://github.com/zitadel/zitadel/commit/c2093ce01507ca8fc811609ff5d391693360c3da
https://github.com/zitadel/zitadel/commit/d04f208486a418a45b884b9ca8433e5ad9790d73
https://github.com/zitadel/zitadel/issues/8213
https://github.com/zitadel/zitadel/pull/8231
https://github.com/zitadel/zitadel/releases/tag/v2.53.8
https://github.com/zitadel/zitadel/releases/tag/v2.54.5
https://github.com/zitadel/zitadel/releases/tag/v2.55.1
https://github.com/zitadel/zitadel/security/advisories/GHSA-cvw9-c57h-3397
CVSS3评分 N/A
  • 攻击路径 N/A
  • 攻击复杂度 N/A
  • 权限要求 N/A
  • 影响范围 N/A
  • 用户交互 N/A
  • 可用性 N/A
  • 保密性 N/A
  • 完整性 N/A
N/A
CWE-ID 漏洞类型
- avd.aliyun.com
weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
N/A Ali_nvd

N/A

N/ACVE编号 CVE-2024-6461利用情况 暂无补丁情况 N/A披露时间 2024-07-04漏洞描述Rejected reason: **REJ
N/A Ali_nvd

N/A

N/ACVE编号 CVE-2024-6463利用情况 暂无补丁情况 N/A披露时间 2024-07-04漏洞描述Rejected reason: **REJ
N/A Ali_nvd

N/A

N/ACVE编号 CVE-2024-6464利用情况 暂无补丁情况 N/A披露时间 2024-07-04漏洞描述Rejected reason: **REJ
评论:0   参与:  0