ZITADEL
cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*
- >= 4.0.0, <= 4.12.1
- >= 3.0.0, <= 3.4.7
- >= 2.68.0, <= 2.71.19
An authentication bypass vulnerability has been identified in ZITADEL's System for Cross-domain Identity Management (SCIM) API, affecting versions 2.68.0 prior to 2.71.19, 3.0.0 prior to 3.4.7, and 4.0.0 prior to 4.12.1. The vulnerability allows unauthenticated attackers to bypass authentication and permission checks by exploiting URL-encoded path values. This exploitation enables the retrieval of sensitive user information, including names, email addresses, phone numbers, addresses, external IDs, and roles. However, due to additional data manipulation checks, attackers cannot modify or delete user data.
Exploitation of this vulnerability allows for unauthorized access to sensitive user information through the SCIM API, with the potential for privacy violations and misuse of personal data.
Users can upgrade to ZITADEL versions 3.4.8 or 4.12.2 to address this vulnerability. For those unable to upgrade, access to the SCIM API can be blocked using a reverse proxy or Web Application Firewall (WAF) rule.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.