ZITADEL, open source authentication management software, uses Go templates to render the login UI. Due to a improper use of the `text/template` instead of the `html/template` package, the Login UI did not sanitize input parameters prior to versions 2.47.3, 2.46.1, 2.45.1, 2.44.3, 2.43.9, 2.42.15, and 2.41.15. An attacker could create a malicious link, where he injected code which would be rendered as part of the login screen. While it was possible to inject HTML including JavaScript, the execution of such scripts would be prevented by the Content Security Policy. Versions 2.47.3, 2.46.1, 2.45.1, 2.44.3, 2.43.9, 2.42.15, and 2.41.15 contain a patch for this issue. No known workarounds are available.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0935 | ZITADEL, open source authentication management software, uses Go templates to render the login UI. Due to a improper use of the `text/template` instead of the `html/template` package, the Login UI did not sanitize input parameters prior to versions 2.47.3, 2.46.1, 2.45.1, 2.44.3, 2.43.9, 2.42.15, and 2.41.15. An attacker could create a malicious link, where he injected code which would be rendered as part of the login screen. While it was possible to inject HTML including JavaScript, the execution of such scripts would be prevented by the Content Security Policy. Versions 2.47.3, 2.46.1, 2.45.1, 2.44.3, 2.43.9, 2.42.15, and 2.41.15 contain a patch for this issue. No known workarounds are available. |
Github GHSA |
GHSA-hfrg-4jwr-jfpj | Improper HTML sanitization in ZITADEL |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 08 Jan 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zitadel
Zitadel zitadel |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* cpe:2.3:a:zitadel:zitadel:2.45.0:-:*:*:*:*:*:* cpe:2.3:a:zitadel:zitadel:2.45.0:rc1:*:*:*:*:*:* cpe:2.3:a:zitadel:zitadel:2.46.0:-:*:*:*:*:*:* cpe:2.3:a:zitadel:zitadel:2.46.0:rc1:*:*:*:*:*:* cpe:2.3:a:zitadel:zitadel:2.46.0:rc2:*:*:*:*:*:* |
|
| Vendors & Products |
Zitadel
Zitadel zitadel |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-13T14:19:08.789Z
Reserved: 2024-03-11T22:45:07.686Z
Link: CVE-2024-28855
Updated: 2024-08-02T00:56:58.167Z
Status : Analyzed
Published: 2024-03-18T22:15:08.963
Modified: 2025-01-08T18:14:28.137
Link: CVE-2024-28855
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA