PT-2025-50564 · Zitadel · Zitadel

CVE-2025-67717

·

Publicado

2025-12-10

·

Atualizado

2026-07-30

CVSS v4.0

5.3

Média

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ZITADEL versions 2.44.0 through 3.4.4 ZITADEL versions 4.0.0-rc.1 through 4.7.1
Description ZITADEL, an open-source identity infrastructure tool, reveals the total number of instance users to authenticated users, irrespective of their permissions. This information disclosure occurs through the totalResult field. While individual user data or personally identifiable information (PII) is not exposed, disclosing the total user count may be sensitive in certain situations.
Recommendations Update to ZITADEL version 3.4.5 or later. Update to ZITADEL version 4.7.2 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-67717
GHSA-F4CF-9RVR-2RCX
GO-2025-4227
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:0037-1

Produtos afetados

Zitadel