CVE-2024-32868
CVSS V2 None
CVSS V3 None
Description
ZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SMS and Email. While ZITADEL already gives administrators the option to define a `Lockout Policy` with a maximum amount of failed password check attempts, there was no such mechanism for (T)OTP checks. This issue has been patched in version 2.50.0.
Overview
- CVE ID
- CVE-2024-32868
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-04-25T23:53:37.235Z
- Last Modified Date
- 2024-04-25T23:53:37.235Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/zitadel/zitadel/security/advisories/GHSA-7j7j-66cv-m239 | x_refsource_CONFIRM |
https://github.com/zitadel/zitadel/releases/tag/v2.50.0 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-32868 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-32868 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-26 08:54:04 | Added to TrackCVE |