CVE-2024-49757: Zitadel User Registration Bypass Vulnerability
Impact Zitadel allows administrators to disable the user self-registration. Due to a missing security check in versions prior to 2.63.4, disabling the "User Registration allowed" option only hid the registration button on the login page. Users could bypass this restriction by directly accessing the registration URL (/ui/login/loginname) and register a user that way.
Patches
2.x versions are fixed on >= 2.64.0 2.63.x versions are fixed on >= 2.63.5 2.62.x versions are fixed on >= 2.62.7 2.61.x versions are fixed on >= 2.61.4 2.60.x versions are fixed on >= 2.60.4 2.59.x versions are fixed on >= 2.59.5 2.58.x versions are fixed on >= 2.58.7
Workarounds Updating to the patched version is the recommended solution.
Questions If you have any questions or comments about this advisory, please email us at security@zitadel.com
Credits Thanks to @sevensolutions and @evilgensec for disclosing this!
Other sources
The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Due to a missing security check in versions prior to 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7, disabling the "User Registration allowed" option only hid the registration button on the login page. Users could bypass this restriction by directly accessing the registration URL (/ui/login/loginname) and register a user that way. Versions 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 contain a patch. No known workarounds are available.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49757?
CVE-2024-49757 is classified as a high-severity vulnerability due to unauthorized user registration capabilities.
How do I fix CVE-2024-49757?
To fix CVE-2024-49757, upgrade to Zitadel version 2.63.5 or later.
What versions of Zitadel are affected by CVE-2024-49757?
CVE-2024-49757 affects Zitadel versions prior to 2.63.4, including 2.58.7 to 2.62.7.
Can users still register if 'User Registration allowed' is disabled in CVE-2024-49757?
Yes, users can still register despite the option being disabled due to a missing security check in the affected versions.
What impact does CVE-2024-49757 have on administrator settings?
CVE-2024-49757 allows users to bypass administrative settings that disable self-registration, compromising the intended user management controls.