diff --git a/advisories/github-reviewed/2024/04/GHSA-7j7j-66cv-m239/GHSA-7j7j-66cv-m239.json b/advisories/github-reviewed/2024/04/GHSA-7j7j-66cv-m239/GHSA-7j7j-66cv-m239.json index c77b8f2d9e1..94b556d2ea2 100644 --- a/advisories/github-reviewed/2024/04/GHSA-7j7j-66cv-m239/GHSA-7j7j-66cv-m239.json +++ b/advisories/github-reviewed/2024/04/GHSA-7j7j-66cv-m239/GHSA-7j7j-66cv-m239.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-7j7j-66cv-m239", - "modified": "2024-04-26T14:41:46Z", + "modified": "2024-06-10T15:41:41Z", "published": "2024-04-25T18:31:31Z", "aliases": [ "CVE-2024-32868" ], "summary": "ZITADEL's Improper Lockout Mechanism Leads to MFA Bypass", - "details": "### Impact\nZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SMS and Email.\n\nWhile ZITADEL already gives administrators the option to define a `Lockout Policy` with a maximum amount of failed password check attempts, there was no such mechanism for (T)OTP checks.\n\n### Patches\n2.x versions are fixed on >= [2.50.0](https://github.com/zitadel/zitadel/releases/tag/v2.50.0)\n\n### Workarounds\nThere is no workaround since a patch is already available.\n\n### References\nNone\n\n### Questions\nIf you have any questions or comments about this advisory, please email us at [security@zitadel.com](mailto:security@zitadel.com)\n\n### Credits\n\nThanks to Jack Moran and Ethan from zxsecurity and Amit Laish from GE Vernova for finding and reporting the vulnerability. \n", + "details": "### Impact\nZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SMS and Email.\n\nWhile ZITADEL already gives administrators the option to define a `Lockout Policy` with a maximum amount of failed password check attempts, there was no such mechanism for (T)OTP checks.\n\n### Patches\n2.x versions are fixed on >= [2.50.0](https://github.com/zitadel/zitadel/releases/tag/v2.50.0)\n\n### Workarounds\nThere is no workaround since a patch is already available.\n\n### References\nNone\n\n### Questions\nIf you have any questions or comments about this advisory, please email us at [security@zitadel.com](mailto:security@zitadel.com)\n\n### Credits\n\nThanks to Jack Moran from Layer 9 Information Security, Ethan from zxsecurity and Amit Laish from GE Vernova for finding and reporting the vulnerability. \n", "severity": [ { "type": "CVSS_V3",