« Volver al listado

CVE-2025-31123

Estado: AnalizadaAlta (8.7)—

Zitadel is open-source identity infrastructure software. A vulnerability existed where expired keys can be used to retrieve tokens. Specifically, ZITADEL fails to properly check the expiration date of the JWT key when used for Authorization Grants. This allows an attacker with an expired key to obtain valid access tokens. This vulnerability does not affect the use of JWT Profile for OAuth 2.0 Client Authentication on the Token and Introspection endpoints, which correctly reject expired keys. This vulnerability is fixed in 2.71.6, 2.70.8, 2.69.9, 2.68.9, 2.67.13, 2.66.16, 2.65.7, 2.64.6, and 2.63.9.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Acceso remoto a servicio de autenticación (ZITADEL) con privilegios requeridos (PR:H) mediante validación deficiente de expiración de claves JWT. Permite obtener tokens válidos (T1078) y potencialmente controlar identidades (T1556).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-31123",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-31123",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-03-31T22:38:16.728894Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.7,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.8,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "zitadel",
          "product": "zitadel",
          "versions": [
            {
              "status": "affected",
              "version": ">= 2.62.0, < 2.63.9"
            },
            {
              "status": "affected",
              "version": ">= 2.64.0-rc.1, < 2.64.6"
            },
            {
              "status": "affected",
              "version": ">= 2.65.0-rc.1, < 2.65.7"
            },
            {
              "status": "affected",
              "version": ">= 2.66.0-rc.1, < 2.66.16"
            },
            {
              "status": "affected",
              "version": ">= 2.67.0-rc.1, < 2.67.13"
            },
            {
              "status": "affected",
              "version": ">= 2.68.0-rc.1, < 2.68.9"
            },
            {
              "status": "affected",
              "version": ">= 2.69.0-rc.1, < 2.69.9"
            },
            {
              "status": "affected",
              "version": ">= 2.70.0-rc.1, < 2.70.8"
            },
            {
              "status": "affected",
              "version": ">= 2.71.0-rc.1, < 2.71.6"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-03-31T20:15:15.547",
  "references": [
    {
      "url": "https://github.com/zitadel/zitadel/commit/315503beabd679f2e6aec0c004f0f9d2f5b53ed3",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/zitadel/zitadel/releases/tag/v2.63.9",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/zitadel/zitadel/releases/tag/v2.64.6",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/zitadel/zitadel/releases/tag/v2.65.7",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/zitadel/zitadel/releases/tag/v2.66.16",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/zitadel/zitadel/releases/tag/v2.67.13",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/zitadel/zitadel/releases/tag/v2.68.9",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/zitadel/zitadel/releases/tag/v2.69.9",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/zitadel/zitadel/releases/tag/v2.70.8",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/zitadel/zitadel/releases/tag/v2.71.6",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/zitadel/zitadel/security/advisories/GHSA-h3q7-347g-qwhf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-324"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Zitadel is open-source identity infrastructure software. A vulnerability existed where expired keys can be used to retrieve tokens. Specifically, ZITADEL fails to properly check the expiration date of the JWT key when used for Authorization Grants. This allows an attacker with an expired key to obtain valid access tokens. This vulnerability does not affect the use of JWT Profile for OAuth 2.0 Client Authentication on the Token and Introspection endpoints, which correctly reject expired keys. This vulnerability is fixed in 2.71.6, 2.70.8, 2.69.9, 2.68.9, 2.67.13, 2.66.16, 2.65.7, 2.64.6, and 2.63.9."
    },
    {
      "lang": "es",
      "value": "Zitadel es un software de infraestructura de identidad de código abierto. Existía una vulnerabilidad que permitía usar claves caducadas para recuperar tokens. En concreto, ZITADEL no verificaba correctamente la fecha de caducidad de la clave JWT al usarla para concesiones de autorización. Esto permitía a un atacante con una clave caducada obtener tokens de acceso válidos. Esta vulnerabilidad no afecta el uso del perfil JWT para la autenticación de cliente OAuth 2.0 en los endpoints de token e introspección, que rechazan correctamente las claves caducadas. Esta vulnerabilidad se ha corregido en las versiones 2.71.6, 2.70.8, 2.69.9, 2.68.9, 2.67.13, 2.66.16, 2.65.7, 2.64.6 y 2.63.9."
    }
  ],
  "lastModified": "2026-06-17T09:09:53.807",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5EB97D4D-7A24-4739-8A7B-D102BCF0889F",
              "versionEndExcluding": "2.63.9",
              "versionStartIncluding": "2.62.0"
            },
            {
              "criteria": "cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D7142F7F-9380-4C7B-A48F-D4A86F5F9759",
              "versionEndExcluding": "2.64.6",
              "versionStartIncluding": "2.64.0"
            },
            {
              "criteria": "cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DE6B033C-D29A-4AFE-B836-F1763E7844F2",
              "versionEndExcluding": "2.65.7",
              "versionStartIncluding": "2.65.0"
            },
            {
              "criteria": "cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5DD1E62B-7DDC-474E-A100-5B0569F5B8FE",
              "versionEndExcluding": "2.66.16",
              "versionStartIncluding": "2.66.0"
            },
            {
              "criteria": "cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E0D9F074-8DBB-4FFC-A104-B33B902FDD02",
              "versionEndExcluding": "2.67.13",
              "versionStartIncluding": "2.67.0"
            },
            {
              "criteria": "cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8DE6D67C-182B-4F08-B4A8-D24A0FD2B66B",
              "versionEndExcluding": "2.68.9",
              "versionStartIncluding": "2.68.0"
            },
            {
              "criteria": "cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A2723F26-27EE-4EA2-845D-93DFA3D2B3F0",
              "versionEndExcluding": "2.69.9",
              "versionStartIncluding": "2.69.0"
            },
            {
              "criteria": "cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FC6090EB-53CF-43AC-AB5B-D51AA2A539C1",
              "versionEndExcluding": "2.70.8",
              "versionStartIncluding": "2.70.0"
            },
            {
              "criteria": "cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3FD8F27A-ED3D-4674-8D57-F348A320A17B",
              "versionEndExcluding": "2.71.6",
              "versionStartIncluding": "2.71.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}