Loading HuntDB...

GHSA-q5qj-x2h5-3945

GitHub Security Advisory

Zitadel exposing internal database user name and host information

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

### Impact

In case ZITADEL could not connect to the database, connection information including db name, username and db host name could be returned to the user.

### Patches

2.x versions are fixed on >= [2.50.3](https://github.com/zitadel/zitadel/releases/tag/v2.50.3)
2.49.x versions are fixed on >= [2.49.5](https://github.com/zitadel/zitadel/releases/tag/v2.49.5)
2.48.x versions are fixed on >= [2.48.5](https://github.com/zitadel/zitadel/releases/tag/v2.48.5)
2.47.x versions are fixed on >= [2.47.10](https://github.com/zitadel/zitadel/releases/tag/v2.47.10)
2.46.x versions are fixed on >= [2.46.7](https://github.com/zitadel/zitadel/releases/tag/v2.46.7)
2.45.x versions are fixed on >= [2.45.7](https://github.com/zitadel/zitadel/releases/tag/v2.45.7)

### Workarounds

There is no workaround since a patch is already available.

### Questions

If you have any questions or comments about this advisory, please email us at [[email protected]](mailto:[email protected])

Affected Packages

Go github.com/zitadel/zitadel
Affected versions: 2.50.0 (fixed in 2.50.3)
Go github.com/zitadel/zitadel
Affected versions: 2.49.0 (fixed in 2.49.5)
Go github.com/zitadel/zitadel
Affected versions: 2.48.0 (fixed in 2.48.5)
Go github.com/zitadel/zitadel
Affected versions: 2.47.0 (fixed in 2.47.10)
Go github.com/zitadel/zitadel
Affected versions: 0 (fixed in 2.45.7)

Related CVEs

Key Information

GHSA ID
GHSA-q5qj-x2h5-3945
Published
May 1, 2024 4:36 PM
Last Modified
July 8, 2024 9:05 PM
CVSS Score
5.0 /10
Primary Ecosystem
Go
Primary Package
github.com/zitadel/zitadel
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 29, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.