QID 995850

Date Published: 2023-11-16

QID 995850: GO (Go) Security Update for github.com/zitadel/zitadel (GHSA-7h8m-vrxx-vr4m)

ZITADEL provides administrators the possibility to define a Lockout Policy with a maximum amount of failed password check attempts. On every failed password check, the amount of failed checks is compared against the configured maximum. Exceeding the limit, will lock the user and prevent further authentication.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.3 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-7h8m-vrxx-vr4m for updates and patch information.
    Vendor References

    CVEs related to QID 995850

    Software Advisories
    Advisory ID Software Component Link
    GHSA-7h8m-vrxx-vr4m github.com/zitadel/zitadel URL Logo github.com/advisories/GHSA-7h8m-vrxx-vr4m