« Volver al listado

CVE-2024-49753

Estado: AnalizadaCrítica (9.1)—

Zitadel is open-source identity infrastructure software. Versions prior to 2.64.1, 2.63.6, 2.62.8, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 have a flaw in the URL validation mechanism of Zitadel actions allows bypassing restrictions intended to block requests to localhost (127.0.0.1). The isHostBlocked check, designed to prevent such requests, can be circumvented by creating a DNS record that resolves to 127.0.0.1. This enables actions to send requests to localhost despite the intended security measures. This vulnerability potentially allows unauthorized access to unsecured internal endpoints, which may contain sensitive information or functionalities. Versions 2.64.1, 2.63.6, 2.62.8, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 contain a patch. No known workarounds are available.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de validación de URL en Zitadel (CWE-20) accesible remotamente sin autenticación (AV:N/PR:N). Permite bypassing de restricciones localhost para acceder a endpoints internos sensibles.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-49753",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-49753",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-25T15:04:29.564973Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 0.7
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.1,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "zitadel",
          "product": "zitadel",
          "versions": [
            {
              "status": "affected",
              "version": ">= 2.64, < 2.64.1"
            },
            {
              "status": "affected",
              "version": ">= 2.63, < 2.63.6"
            },
            {
              "status": "affected",
              "version": ">= 2.62, < 2.62.8"
            },
            {
              "status": "affected",
              "version": ">= 2.61, < 2.61.4"
            },
            {
              "status": "affected",
              "version": ">= 2.60, < 2.60.4"
            },
            {
              "status": "affected",
              "version": ">= 2.59, < 2.59.5"
            },
            {
              "status": "affected",
              "version": "< 2.58.7"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*"
          ],
          "vendor": "zitadel",
          "product": "zitadel",
          "versions": [
            {
              "status": "affected",
              "version": "2.64",
              "lessThan": "2.64.1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2.63",
              "lessThan": "2.63.6",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2.62",
              "lessThan": "2.62.8",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2.61",
              "lessThan": "2.61.4",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2.60",
              "lessThan": "2.60.4",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2.59",
              "lessThan": "2.59.5",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2.58.7",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-10-25T14:15:12.280",
  "references": [
    {
      "url": "https://github.com/zitadel/zitadel/releases/tag/v2.58.7",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/zitadel/zitadel/releases/tag/v2.59.5",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/zitadel/zitadel/releases/tag/v2.60.4",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/zitadel/zitadel/releases/tag/v2.61.4",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/zitadel/zitadel/releases/tag/v2.62.8",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/zitadel/zitadel/releases/tag/v2.63.6",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/zitadel/zitadel/releases/tag/v2.64.1",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/zitadel/zitadel/security/advisories/GHSA-6cf5-w9h3-4rqv",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Zitadel is open-source identity infrastructure software. Versions prior to 2.64.1, 2.63.6, 2.62.8, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 have a flaw in the URL validation mechanism of Zitadel actions allows bypassing restrictions intended to block requests to localhost (127.0.0.1). The isHostBlocked check, designed to prevent such requests, can be circumvented by creating a DNS record that resolves to 127.0.0.1. This enables actions to send requests to localhost despite the intended security measures. This vulnerability potentially allows unauthorized access to unsecured internal endpoints, which may contain sensitive information or functionalities. Versions 2.64.1, 2.63.6, 2.62.8, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 contain a patch. No known workarounds are available."
    },
    {
      "lang": "es",
      "value": "Zitadel es un software de infraestructura de identidad de código abierto. Las versiones anteriores a 2.64.1, 2.63.6, 2.62.8, 2.61.4, 2.60.4, 2.59.5 y 2.58.7 tienen una falla en el mecanismo de validación de URL de las acciones de Zitadel que permite eludir las restricciones destinadas a bloquear las solicitudes a localhost (127.0.0.1). La comprobación isHostBlocked, diseñada para evitar dichas solicitudes, se puede eludir mediante la creación de un registro DNS que se resuelva en 127.0.0.1. Esto permite que las acciones envíen solicitudes a localhost a pesar de las medidas de seguridad previstas. Esta vulnerabilidad potencialmente permite el acceso no autorizado a endpoints internos no seguros, que pueden contener información o funcionalidades confidenciales. Las versiones 2.64.1, 2.63.6, 2.62.8, 2.61.4, 2.60.4, 2.59.5 y 2.58.7 contienen un parche. No se conocen workarounds disponibles."
    }
  ],
  "lastModified": "2026-06-17T08:00:23.030",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9901A715-7590-4CDB-9862-A37A7818015D",
              "versionEndExcluding": "2.58.7"
            },
            {
              "criteria": "cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F3D36B9D-2968-4999-99BA-FB1DB65603E8",
              "versionEndExcluding": "2.59.5",
              "versionStartIncluding": "2.59.0"
            },
            {
              "criteria": "cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CA74E6EF-BB93-4B3D-8F5A-BA5D9E018EE7",
              "versionEndExcluding": "2.60.4",
              "versionStartIncluding": "2.60.0"
            },
            {
              "criteria": "cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "893A9BBF-8ED6-4F19-B939-D48686E074A8",
              "versionEndExcluding": "2.61.4",
              "versionStartIncluding": "2.61.0"
            },
            {
              "criteria": "cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "13A35D80-C480-4A14-8168-0C12E2785FD2",
              "versionEndExcluding": "2.62.8",
              "versionStartIncluding": "2.62.0"
            },
            {
              "criteria": "cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "34C31619-155C-4AB5-B841-C4D32FBBF054",
              "versionEndExcluding": "2.63.6",
              "versionStartIncluding": "2.63.0"
            },
            {
              "criteria": "cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F286955F-9DC7-466D-9D28-965CCF375F22",
              "versionEndExcluding": "2.64.1",
              "versionStartIncluding": "2.64.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}