Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*", "matchCriteriaId": "223DDD74-92C5-4069-9422-B64A3D12EF6F", "versionEndExcluding": "2.38.2", "vulnerable": true}, {"criteria": "cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2ED84934-B055-4AA2-A96F-168846A8F62A", "versionEndExcluding": "2.39.2", "versionStartIncluding": "2.39.0", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "descriptions": [{"lang": "en", "value": "ZITADEL is an identity infrastructure management system. ZITADEL users can upload their own avatar image using various image types including SVG. SVG can include scripts, such as javascript, which can be executed during rendering. Due to a missing security header, an attacker could inject code to an SVG to gain access to the victim\u2019s account in certain scenarios. A victim would need to directly open the malicious image in the browser, where a single session in ZITADEL needs to be active for this exploit to work. If the possible victim had multiple or no active sessions in ZITADEL, the attack would not succeed. This issue has been patched in version 2.39.2 and 2.38.2."}, {"lang": "es", "value": "ZITADEL es un sistema de gesti\u00f3n de infraestructura de identidad. Los usuarios de ZITADEL pueden cargar su propia imagen de avatar utilizando varios tipos de im\u00e1genes, incluido SVG. SVG puede incluir scripts, como javascript, que se pueden ejecutar durante el renderizado. Debido a la falta de un encabezado de seguridad, un atacante podr\u00eda inyectar c\u00f3digo en un SVG para obtener acceso a la cuenta de la v\u00edctima en ciertos escenarios. Una v\u00edctima necesitar\u00eda abrir directamente la imagen maliciosa en el navegador, donde debe haber una \u00fanica sesi\u00f3n activa en ZITADEL para que este exploit funcione. Si la posible v\u00edctima tuviera varias sesiones activas o ninguna en ZITADEL, el ataque no tendr\u00eda \u00e9xito. Este problema se solucion\u00f3 en las versiones 2.39.2 y 2.38.2."}], "id": "CVE-2023-46238", "lastModified": "2024-11-21T08:28:08.540", "metrics": {"cvssMetricV31": [{"cvssData": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 8.7, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "CHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N", "version": "3.1"}, "exploitabilityScore": 2.3, "impactScore": 5.8, "source": "security-advisories@github.com", "type": "Secondary"}, {"cvssData": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 5.4, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "privilegesRequired": "LOW", "scope": "CHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N", "version": "3.1"}, "exploitabilityScore": 2.3, "impactScore": 2.7, "source": "nvd@nist.gov", "type": "Primary"}]}, "published": "2023-10-26T15:15:09.173", "references": [{"source": "security-advisories@github.com", "tags": ["Patch"], "url": "https://github.com/zitadel/zitadel/releases/tag/v2.38.2"}, {"source": "security-advisories@github.com", "tags": ["Patch"], "url": "https://github.com/zitadel/zitadel/releases/tag/v2.39.2"}, {"source": "security-advisories@github.com", "tags": ["Vendor Advisory"], "url": "https://github.com/zitadel/zitadel/security/advisories/GHSA-954h-jrpm-72pm"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Patch"], "url": "https://github.com/zitadel/zitadel/releases/tag/v2.38.2"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Patch"], "url": "https://github.com/zitadel/zitadel/releases/tag/v2.39.2"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Vendor Advisory"], "url": "https://github.com/zitadel/zitadel/security/advisories/GHSA-954h-jrpm-72pm"}], "sourceIdentifier": "security-advisories@github.com", "vulnStatus": "Modified", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-79"}], "source": "security-advisories@github.com", "type": "Secondary"}, {"description": [{"lang": "en", "value": "CWE-79"}], "source": "nvd@nist.gov", "type": "Primary"}]}