ZITADEL, open source authentication management software, uses Go templates to render the login UI. Due to a improper use of the `text/template` instead of the `html/template` package, the Login UI did not sanitize input parameters prior to versions 2.47.3, 2.46.1, 2.45.1, 2.44.3, 2.43.9, 2.42.15, and 2.41.15. An attacker could create a malicious link, where he injected code which would be rendered as part of the login screen. While it was possible to inject HTML including JavaScript, the execution of such scripts would be prevented by the Content Security Policy. Versions 2.47.3, 2.46.1, 2.45.1, 2.44.3, 2.43.9, 2.42.15, and 2.41.15 contain a patch for this issue. No known workarounds are available.
History

Wed, 08 Jan 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Zitadel
Zitadel zitadel
Weaknesses CWE-79
CPEs cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*
cpe:2.3:a:zitadel:zitadel:2.45.0:-:*:*:*:*:*:*
cpe:2.3:a:zitadel:zitadel:2.45.0:rc1:*:*:*:*:*:*
cpe:2.3:a:zitadel:zitadel:2.46.0:-:*:*:*:*:*:*
cpe:2.3:a:zitadel:zitadel:2.46.0:rc1:*:*:*:*:*:*
cpe:2.3:a:zitadel:zitadel:2.46.0:rc2:*:*:*:*:*:*
Vendors & Products Zitadel
Zitadel zitadel

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-03-18T21:46:47.314Z

Updated: 2024-08-13T14:19:08.789Z

Reserved: 2024-03-11T22:45:07.686Z

Link: CVE-2024-28855

cve-icon Vulnrichment

Updated: 2024-08-02T00:56:58.167Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-18T22:15:08.963

Modified: 2025-01-08T18:14:28.137

Link: CVE-2024-28855

cve-icon Redhat

No data.