VDB
GO-2024-3216
GO-2024-3216
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Denied Host Validation Bypass in Zitadel Actions in github.com/zitadel/zitadel
Risk Scores
CVSS v4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | zitadel/zitadel | 0, 0 |
Timeline
- Oct 28, 2024 CVE Published
- Oct 28, 2024 CVE Updated
- May 1, 2026 Security Advisory
References
- https://github.com/zitadel/zitadel/security/advisories/GHSA-6cf5-w9h3-4rqv advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-49753 advisory
- https://github.com/zitadel/zitadel/releases/tag/v2.58.7 url
- https://github.com/zitadel/zitadel/releases/tag/v2.59.5 url
- https://github.com/zitadel/zitadel/releases/tag/v2.60.4 url
- https://github.com/zitadel/zitadel/releases/tag/v2.61.4 url
- https://github.com/zitadel/zitadel/releases/tag/v2.62.8 url
- https://github.com/zitadel/zitadel/releases/tag/v2.63.6 url
- https://github.com/zitadel/zitadel/releases/tag/v2.64.1 url