ZITADEL, open source authentication management software, uses Go templates to render the login UI. Under certain circumstances an action could set reserved claims managed by ZITADEL. For example it would be possible to set the claim `urn:zitadel:iam:user:resourceowner:name`. To compensate for this we introduced a protection that does prevent actions from changing claims that start with `urn:zitadel:iam`. This vulnerability is fixed in 2.48.3, 2.47.8, 2.46.5, 2.45.5, 2.44.7, 2.43.11, and 2.42.17.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-03-27T19:59:24.734Z

Updated: 2024-08-13T14:07:12.217Z

Reserved: 2024-03-21T15:12:08.998Z

Link: CVE-2024-29892

cve-icon Vulnrichment

Updated: 2024-08-02T01:17:58.115Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-27T20:15:08.303

Modified: 2024-03-28T02:01:13.303

Link: CVE-2024-29892

cve-icon Redhat

No data.