SCA: security update for github.com/zitadel/zitadel (GHSA-mq4x-r2w3-j7mr)

high Tenable Cloud Security Plugin ID 417078

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Zitadel is an open source identity management system. Zitadel uses a cookie to identify the user agent
(browser) and its user sessions. Although the cookie was handled according to best practices, it was
accessible on subdomains of the ZITADEL instance. An attacker could take advantage of this and provide a
malicious link hosted on the subdomain to the user to gain access to the victim’s account in certain
scenarios. A possible victim would need to login through the malicious link for this exploit to work. If
the possible victim already had the cookie present, the attack would not succeed. The attack would further
only be possible if there was an initial vulnerability on the subdomain. This could either be the attacker
being able to control DNS or a XSS vulnerability in an application hosted on a subdomain. Versions 2.46.0,
2.45.1, and 2.44.3 have been patched. Zitadel recommends upgrading to the latest versions available in due
course. Note that applying the patch will invalidate the current cookie and thus users will need to start
a new session and existing sessions (user selection) will be empty. For self-hosted environments unable to
upgrade to a patched version, prevent setting the following cookie name on subdomains of your Zitadel
instance (e.g. within your WAF): `__Secure-zitadel-useragent`. (CVE-2024-28197)

See Also

https://github.com/advisories/GHSA-mq4x-r2w3-j7mr

Plugin Details

Severity: High

ID: 417078

Version: Revision 1.11

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.8

Percentile: 57.51

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 6.2

Temporal Score: 4.6

Vector: CVSS2#AV:A/AC:H/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2024-28197

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 7.1

Threat Score: 4.1

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 3/11/2024

Vulnerability Publication Date: 3/11/2024

Reference Information

CVE: CVE-2024-28197