blob: 4ad71618a7b910b816efc1eedb1cd87d5571a39b [file] [edit]
id: GO-2025-4212
modules:
- module: github.com/zitadel/zitadel
versions:
- fixed: 1.80.0-v2.20.0.20251208091519-4c879b47334e
- introduced: 1.83.4
non_go_versions:
- introduced: 4.0.0-rc.1
- fixed: 4.7.1
unsupported_versions:
- last_affected: 1.87.5
vulnerable_at: 1.87.5
summary: |-
ZITADEL Vulnerable to Account Takeover Due to Improper Instance Validation in V2
Login in github.com/zitadel/zitadel
ghsas:
- GHSA-pfrf-9r5f-73f5
references:
- advisory: https://github.com/zitadel/zitadel/security/advisories/GHSA-pfrf-9r5f-73f5
- fix: https://github.com/zitadel/zitadel/commit/4c879b47334e01d4fcab921ac1b44eda39acdb96
notes:
- fix: 'module merge error: could not merge versions of module github.com/zitadel/zitadel: introduced and fixed versions must alternate'
source:
id: GHSA-pfrf-9r5f-73f5
created: 2025-12-15T12:57:05.583246848-05:00
review_status: UNREVIEWED