ZITADEL is an open source identity management platform. From version 4.0.0 to 4.12.0, a vulnerability in Zitadels login V2 UI allowed users to bypass login behavior and security policies and self-register new accounts or sign in using password even if corresponding options were disabled in their organizaton. This issue has been patched in version 4.12.1.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Zitadel | Zitadel | 4.0.0 (including) | 4.12.1 (excluding) |