CVE-2023-22492
NixOS vulnerability analysis and mitigation

Overview

ZITADEL, a combination of Auth0 and Keycloak, was found to have a vulnerability (CVE-2023-22492) related to RefreshTokens, an OAuth 2.0 feature that allows applications to retrieve new access tokens and refresh user sessions without UI interaction. The vulnerability was discovered where RefreshTokens were not being invalidated when a user was locked or deactivated. This issue was disclosed on January 11, 2023, affecting ZITADEL versions from 2.0.0 to versions before 2.17.3 and 2.16.4 (GitHub Advisory).

Technical details

The vulnerability stems from a failure to properly invalidate refresh tokens upon user deactivation or lockout. When a user was locked or deactivated, they could still obtain valid access tokens through a refresh token grant, though they couldn't create new sessions if already logged out. The vulnerability has a CVSS v3.1 score of 5.9 (Medium), with a vector string of CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N, indicating network vector attack with high complexity, requiring low privileges and no user interaction (GitHub Advisory, NVD).

Impact

The vulnerability allowed deactivated or locked users to maintain access to the system through existing refresh tokens, potentially bypassing intended access restrictions. While the impact was limited by the refresh token's configured expiration time, it could lead to unauthorized access until the token expired (GitHub Advisory).

Exploitability

The vulnerability requires an attacker to have an existing refresh token before their account was locked or deactivated. The exploitation is limited to the configured RefreshTokenExpiration time period, and new sessions cannot be created if the user was already logged out (GitHub Advisory).

Mitigation and workarounds

The issue has been patched in ZITADEL versions 2.17.3 and 2.16.4. As a workaround for unpatched systems, administrators should ensure the RefreshTokenExpiration in the OIDC settings is configured according to their security requirements. ZITADEL recommends upgrading to the latest available versions (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management