Loading HuntDB...

GHSA-cvw9-c57h-3397

GitHub Security Advisory

ZITADEL Vulnerable to Session Information Leakage

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

### Impact

ZITADEL provides users the ability to list all user sessions of the current user agent (browser) by API and in the Console UI.

Due to a missing check, user sessions without that information (e.g. when created though the session service) were incorrectly listed exposing potentially other user's sessions.

Note that the Login UI was never affected and there was no possibility to take over such a session.

### Patches

2.x versions are fixed on >= [2.55.1](https://github.com/zitadel/zitadel/releases/tag/v2.55.1)
2.54.x versions are fixed on >= [2.54.5](https://github.com/zitadel/zitadel/releases/tag/v2.54.5)
2.53.x versions are fixed on >= [2.53.8](https://github.com/zitadel/zitadel/releases/tag/v2.53.8)

ZITADEL recommends upgrading to the latest versions available in due course.

### Workarounds

There is no workaround since a patch is already available.

### References

- https://github.com/zitadel/zitadel/pull/8231
- https://discord.com/channels/927474939156643850/1254096852937347153
- https://github.com/zitadel/zitadel/issues/8213

### Questions
If you have any questions or comments about this advisory, please email us at [[email protected]](mailto:[email protected])

### Credits
Thanks to @cybertransformer, @Avolicious, @AmirhoseinBrz and @srividyaj for finding and reporting the vulnerability.

Affected Packages

Go github.com/zitadel/zitadel
Affected versions: 2.0.0 (fixed in 2.53.8)
Go github.com/zitadel/zitadel
Affected versions: 2.54.0 (fixed in 2.54.5)
Go github.com/zitadel/zitadel
Affected versions: 2.55.0 (fixed in 2.55.1)

Related CVEs

Key Information

GHSA ID
GHSA-cvw9-c57h-3397
Published
July 5, 2024 8:03 PM
Last Modified
July 9, 2024 9:56 PM
CVSS Score
5.0 /10
Primary Ecosystem
Go
Primary Package
github.com/zitadel/zitadel
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 29, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.