
Cloud Vulnerability DB
A community-led vulnerabilities database
ZITADEL, a combination of Auth0 and Keycloak, was found to have a vulnerability (CVE-2023-22492) related to RefreshTokens, an OAuth 2.0 feature that allows applications to retrieve new access tokens and refresh user sessions without UI interaction. The vulnerability was discovered where RefreshTokens were not being invalidated when a user was locked or deactivated. This issue was disclosed on January 11, 2023, affecting ZITADEL versions from 2.0.0 to versions before 2.17.3 and 2.16.4 (GitHub Advisory).
The vulnerability stems from a failure to properly invalidate refresh tokens upon user deactivation or lockout. When a user was locked or deactivated, they could still obtain valid access tokens through a refresh token grant, though they couldn't create new sessions if already logged out. The vulnerability has a CVSS v3.1 score of 5.9 (Medium), with a vector string of CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N, indicating network vector attack with high complexity, requiring low privileges and no user interaction (GitHub Advisory, NVD).
The vulnerability allowed deactivated or locked users to maintain access to the system through existing refresh tokens, potentially bypassing intended access restrictions. While the impact was limited by the refresh token's configured expiration time, it could lead to unauthorized access until the token expired (GitHub Advisory).
The vulnerability requires an attacker to have an existing refresh token before their account was locked or deactivated. The exploitation is limited to the configured RefreshTokenExpiration time period, and new sessions cannot be created if the user was already logged out (GitHub Advisory).
The issue has been patched in ZITADEL versions 2.17.3 and 2.16.4. As a workaround for unpatched systems, administrators should ensure the RefreshTokenExpiration in the OIDC settings is configured according to their security requirements. ZITADEL recommends upgrading to the latest available versions (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."