ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, full-read SSRF vulnerability. The ZITADEL Login UI (V2) treats the x-zitadel-forward-host header as a trusted fallback for all deployments, including self-hosted instances. This allows an unauthenticated attacker to force the server to make HTTP requests to arbitrary domains, such as internal addresses, and read the responses, enabling data exfiltration and bypassing network-segmentation controls. This issue is fixed in version 4.7.1.
ZITADEL Login UI (V2) unconditionally treats the HTTP header `x-zitadel-forward-host` as a trusted target source for all deployments, including self-hosted installations. An unauthenticated attacker can send a request with an arbitrarily set `x-zitadel-forward-host` header pointing to an internal network address or external domain. The ZITADEL server will execute the request to the specified address and return its contents to the attacker, enabling full-read SSRF.
An attacker can gain unauthorized access to internal network resources that are not publicly accessible, exfiltrate sensitive data, and bypass network segmentation mechanisms and access controls based on network topology.
Update ZITADEL to version 4.7.1, where the issue has been fixed. The patch is available in the project's GitHub repository (commit 4c879b47334e01d4fcab921ac1b44eda39acdb96). Until the update is applied, it is recommended to restrict access to the Login UI interface at the firewall or reverse proxy level and monitor unusual outgoing requests from the server.
ZITADEL in versions 4.7.0 and lower — affects all deployments, including self-hosted installations using ZITADEL Login UI V2.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:NZitadel
APPZitadel4.0.0 – 4.7.1 (excl.)
Related vulnerabilities
XSS w Zitadel Login V2 — możliwe przejęcie konta przez /saml-post
IDOR w Zitadel Admin API umożliwia modyfikację wrażliwych ustawień
ZITADEL is an open source identity management platform. From 2.71.11 to before 3.4.10 and 4.15.0, a vulnerabil...
ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a vulnerability in Zitadel'...
ZITADEL is an open source identity management platform. From 2.68.0 to before 3.4.8 and 4.12.2, Zitadel provid...