ZITADEL, open source authentication management software, uses Go templates to render the login UI. Under certain circumstances an action could set reserved claims managed by ZITADEL. For example it would be possible to set the claim `urn:zitadel:iam:user:resourceowner:name`. To compensate for this we introduced a protection that does prevent actions from changing claims that start with `urn:zitadel:iam`. This vulnerability is fixed in 2.48.3, 2.47.8, 2.46.5, 2.45.5, 2.44.7, 2.43.11, and 2.42.17.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-03-27T19:59:24.734Z
Updated: 2024-08-13T14:07:12.217Z
Reserved: 2024-03-21T15:12:08.998Z
Link: CVE-2024-29892
Vulnrichment
Updated: 2024-08-02T01:17:58.115Z
NVD
Status : Awaiting Analysis
Published: 2024-03-27T20:15:08.303
Modified: 2024-03-28T02:01:13.303
Link: CVE-2024-29892
Redhat
No data.