CVE-2024-32868: ZITADEL's Improper Lockout Mechanism Leads to MFA Bypass
Impact ZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SMS and Email.
While ZITADEL already gives administrators the option to define a Lockout Policy with a maximum amount of failed password check attempts, there was no such mechanism for (T)OTP checks.
Patches 2.x versions are fixed on >= 2.50.0
Workarounds There is no workaround since a patch is already available.
References None
Questions If you have any questions or comments about this advisory, please email us at security@zitadel.com
Credits
Thanks to Jack Moran from Layer 9 Information Security, Ethan from zxsecurity and Amit Laish from GE Vernova for finding and reporting the vulnerability.
Other sources
ZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SMS and Email. While ZITADEL already gives administrators the option to define a Lockout Policy with a maximum amount of failed password check attempts, there was no such mechanism for (T)OTP checks. This issue has been patched in version 2.50.0.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32868?
CVE-2024-32868 is classified as a critical vulnerability that can allow attackers to bypass lockout policies.
How do I fix CVE-2024-32868?
To mitigate CVE-2024-32868, upgrade to ZITADEL version 2.50.0 or later.
What does CVE-2024-32868 affect?
CVE-2024-32868 affects the ZITADEL authentication system specifically prior to version 2.50.0.
What are the main issues with CVE-2024-32868?
CVE-2024-32868 allows for potential brute-force attacks due to insufficient lockout policies in the ZITADEL framework.
Who is affected by CVE-2024-32868?
Any organization using ZITADEL versions below 2.50.0 is vulnerable to CVE-2024-32868.