Medium severity6.1NVD Advisory· Published Mar 27, 2024· Updated Jun 17, 2026
CVE-2024-29892
CVE-2024-29892
Description
ZITADEL, open source authentication management software, uses Go templates to render the login UI. Under certain circumstances an action could set reserved claims managed by ZITADEL. For example it would be possible to set the claim urn:zitadel:iam:user:resourceowner:name. To compensate for this we introduced a protection that does prevent actions from changing claims that start with urn:zitadel:iam. This vulnerability is fixed in 2.48.3, 2.47.8, 2.46.5, 2.45.5, 2.44.7, 2.43.11, and 2.42.17.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/zitadel/zitadelGo | < 2.42.17 | 2.42.17 |
github.com/zitadel/zitadelGo | >= 2.43.0, < 2.43.11 | 2.43.11 |
github.com/zitadel/zitadelGo | >= 2.44.0, < 2.44.7 | 2.44.7 |
github.com/zitadel/zitadelGo | >= 2.45.0, < 2.45.5 | 2.45.5 |
github.com/zitadel/zitadelGo | >= 2.46.0, < 2.46.5 | 2.46.5 |
github.com/zitadel/zitadelGo | >= 2.47.0, < 2.47.8 | 2.47.8 |
github.com/zitadel/zitadelGo | >= 2.48.0, < 2.48.3 | 2.48.3 |
Affected products
3Patches
Vulnerability mechanics
References
10- github.com/advisories/GHSA-gp8g-f42f-95q2ghsaADVISORY
- github.com/zitadel/zitadel/security/advisories/GHSA-gp8g-f42f-95q2nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-29892ghsaADVISORY
- github.com/zitadel/zitadel/releases/tag/v2.42.17nvdRelease NotesWEB
- github.com/zitadel/zitadel/releases/tag/v2.43.11nvdRelease NotesWEB
- github.com/zitadel/zitadel/releases/tag/v2.44.7nvdRelease NotesWEB
- github.com/zitadel/zitadel/releases/tag/v2.45.5nvdRelease NotesWEB
- github.com/zitadel/zitadel/releases/tag/v2.46.5nvdRelease NotesWEB
- github.com/zitadel/zitadel/releases/tag/v2.47.8nvdRelease NotesWEB
- github.com/zitadel/zitadel/releases/tag/v2.48.3nvdRelease NotesWEB
News mentions
0No linked articles in our index yet.