ZITADEL is an open-source identity infrastructure tool. ZITADEL provides users the ability to list all user sessions of the current user agent (browser). Starting in version 2.53.0 and prior to versions 2.53.8, 2.54.5, and 2.55.1, due to a missing check, user sessions without that information (e.g. when created though the session service) were incorrectly listed exposing potentially other user's sessions. Versions 2.55.1, 2.54.5, and 2.53.8 contain a fix for the issue. There is no workaround since a patch is already available.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-07-03 20:15
Updated : 2024-07-05 12:55
NVD link : CVE-2024-39683
Mitre link : CVE-2024-39683
CVE.ORG link : CVE-2024-39683
JSON object : View
Products Affected
No product.
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor