296,869
Total vulnerabilities in the database
ZITADEL, open source authentication management software, uses Go templates to render the login UI. Due to a improper use of the text/template instead of the html/template package, the Login UI did not sanitize input parameters prior to versions 2.47.3, 2.46.1, 2.45.1, 2.44.3, 2.43.9, 2.42.15, and 2.41.15. An attacker could create a malicious link, where he injected code which would be rendered as part of the login screen. While it was possible to inject HTML including JavaScript, the execution of such scripts would be prevented by the Content Security Policy. Versions 2.47.3, 2.46.1, 2.45.1, 2.44.3, 2.43.9, 2.42.15, and 2.41.15 contain a patch for this issue. No known workarounds are available.
| Software | From | Fixed in | 
|---|---|---|
                                                                        
                                                                             
                                                                                    
                                                                                github.com/zitadel/zitadel
                                                                            
                                                                        
                                                                     | 
                                                                    - | 2.41.15 | 
                                                                        
                                                                             
                                                                                    
                                                                                github.com/zitadel/zitadel
                                                                            
                                                                        
                                                                     | 
                                                                    2.42.0 | 2.42.15 | 
                                                                        
                                                                             
                                                                                    
                                                                                github.com/zitadel/zitadel
                                                                            
                                                                        
                                                                     | 
                                                                    2.43.0 | 2.43.9 | 
                                                                        
                                                                             
                                                                                    
                                                                                github.com/zitadel/zitadel
                                                                            
                                                                        
                                                                     | 
                                                                    2.44.0 | 2.44.3 | 
                                                                        
                                                                             
                                                                                    
                                                                                github.com/zitadel/zitadel
                                                                            
                                                                        
                                                                     | 
                                                                    2.45.0 | 2.45.0.x | 
                                                                        
                                                                             
                                                                                    
                                                                                github.com/zitadel/zitadel
                                                                            
                                                                        
                                                                     | 
                                                                    2.45.0 | 2.45.1 | 
                                                                        
                                                                             
                                                                                    
                                                                                github.com/zitadel/zitadel
                                                                            
                                                                        
                                                                     | 
                                                                    2.46.0 | 2.46.0.x | 
                                                                        
                                                                             
                                                                                    
                                                                                github.com/zitadel/zitadel
                                                                            
                                                                        
                                                                     | 
                                                                    2.46.0 | 2.46.1 | 
                                                                        
                                                                             
                                                                                    
                                                                                github.com/zitadel/zitadel
                                                                            
                                                                        
                                                                     | 
                                                                    2.47.0 | 2.47.4 | 
| zitadel / zitadel | 2.47.0 | 2.47.4 | 
| zitadel / zitadel | 2.44.0 | 2.44.3 | 
| zitadel / zitadel | 2.43.0 | 2.43.9 | 
| zitadel / zitadel | 2.42.0 | 2.42.15 | 
| zitadel / zitadel | - | 2.41.15 | 
| zitadel / zitadel | 2.45.0 | 2.45.0.x | 
| zitadel / zitadel | 2.46.0 | 2.46.0.x | 
| zitadel / zitadel | 2.45.0-rc1 | 2.45.0-rc1.x | 
| zitadel / zitadel | 2.46.0-rc1 | 2.46.0-rc1.x | 
| zitadel / zitadel | 2.46.0-rc2 | 2.46.0-rc2.x |