CVE-2024-41953
unknown
CVSS v3
—
CVSS v2
—
VIR risk
—
Description
ZITADEL has improper HTML sanitization in emails and Console UI in github.com/zitadel/zitadel
Predictions
Exploit likelihood
30%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Go | github.com/zitadel/zitadel | >=1.80.1,<2.52.3 | 2.52.3 |
| Go | github.com/zitadel/zitadel | >=2.53.0,<2.53.9 | 2.53.9 |
| Go | github.com/zitadel/zitadel | >=2.54.0,<2.54.8 | 2.54.8 |
| Go | github.com/zitadel/zitadel | >=2.55.0,<2.55.5 | 2.55.5 |
| Go | github.com/zitadel/zitadel | >=2.56.0,<2.56.2 | 2.56.2 |
| Go | github.com/zitadel/zitadel | >=2.57.0,<2.57.1 | 2.57.1 |
| Go | github.com/zitadel/zitadel | >=2.58.0,<2.58.1 | 2.58.1 |
| Go | github.com/zitadel/zitadel | <0.0.0-20240731122110-189505c80fa6 | 0.0.0-20240731122110-189505c80fa6 |
| Go | github.com/zitadel/zitadel | >=0.0.0,<1.80.0-v2.20.0.20240731122110-189505c80fa6 | 1.80.0-v2.20.0.20240731122110-189505c80fa6 |
| Go | github.com/zitadel/zitadel | | |
References
- https://github.com/zitadel/zitadel/security/advisories/GHSA-v333-7h2p-5fhv
- https://nvd.nist.gov/vuln/detail/CVE-2024-41953
- https://github.com/zitadel/zitadel/commit/0e1f99e987b5851caec45a72660fe9f67e425747
- https://github.com/zitadel/zitadel/commit/38da602ee1cfc35c0d7918c298fbfc3f3674133b
- https://github.com/zitadel/zitadel/commit/4b59cac67bb89c1f3f84a2041dd273d11151d29f
- https://github.com/zitadel/zitadel/commit/c1a3fc72dde16e987d8a09aa291e7c2edfc928f7
- https://github.com/zitadel/zitadel/commit/c353f82f89c6982c0888c6763363296cf4263cb2
- https://github.com/zitadel/zitadel/commit/d04ac6df8f2f0243e649b802a8bfa6176cef0923
- https://github.com/zitadel/zitadel/commit/f846616a3f022e88e3ea8cea05d3254ad86f1615
- https://pkg.go.dev/vuln/GO-2024-3015
- https://github.com/zitadel/zitadel/releases/tag/v2.58.1
- https://github.com/zitadel/zitadel/releases/tag/v2.57.1
- https://github.com/zitadel/zitadel/releases/tag/v2.56.2
- https://github.com/zitadel/zitadel/releases/tag/v2.55.5
- https://github.com/zitadel/zitadel/releases/tag/v2.54.8
- https://github.com/zitadel/zitadel/releases/tag/v2.53.9
- https://github.com/zitadel/zitadel/releases/tag/v2.52.3
- https://github.com/zitadel/zitadel
Verify integrity in audit chain (admin only). AS-IS.