ZITADEL is an open-source identity infrastructure tool. ZITADEL provides users the ability to list all user sessions of the current user agent (browser). Starting in version 2.53.0 and prior to versions 2.53.8, 2.54.5, and 2.55.1, due to a missing check, user sessions without that information (e.g. when created though the session service) were incorrectly listed exposing potentially other user's sessions. Versions 2.55.1, 2.54.5, and 2.53.8 contain a fix for the issue. There is no workaround since a patch is already available.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-07-03T19:20:08.880Z
Updated: 2024-08-02T04:26:15.915Z
Reserved: 2024-06-27T18:44:13.034Z
Link: CVE-2024-39683
Vulnrichment
Updated: 2024-07-05T18:37:44.593Z
NVD
Status : Awaiting Analysis
Published: 2024-07-03T20:15:04.840
Modified: 2024-11-21T09:28:12.830
Link: CVE-2024-39683
Redhat
No data.