CVE-2025-64103 (CNNVD-202510-3961)
中文标题:
ZITADEL 安全漏洞
英文标题:
Zitadel Bypass Second Authentication Factor
漏洞描述
中文描述:
ZITADEL是瑞士ZITADEL开源的一个 Auth0、Firebase Auth、AWS Cognito 以及为容器和无服务器时代构建的 Keycloak 的现代开源替代方案。 ZITADEL 2.53.6版本、2.54.3版本和2.55.0版本存在安全漏洞,该漏洞源于未强制要求多因素认证,可能导致攻击者绕过密码验证并仅针对TOTP代码进行攻击。
英文描述:
Starting from 2.53.6, 2.54.3, and 2.55.0, Zitadel only required multi factor authentication in case the login policy has either enabled requireMFA or requireMFAForLocalUsers. If a user has set up MFA without this requirement, Zitadel would consider single factor auhtenticated sessions as valid as well and not require multiple factors. Bypassing second authentication factors weakens multifactor authentication and enables attackers to bypass the more secure factor. An attacker can target the TOTP code alone, only six digits, bypassing password verification entirely and potentially compromising accounts with 2FA enabled. This vulnerability is fixed in 4.6.0, 3.4.3, and 2.71.18.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| zitadel | zitadel | >= 4.0.0-rc.1, < 4.6.0 | - | - |
cpe:2.3:a:zitadel:zitadel:>=_4.0.0-rc.1,_<_4.6.0:*:*:*:*:*:*:*
|
| zitadel | zitadel | >= 3.0.0-rc.1, < 3.4.3 | - | - |
cpe:2.3:a:zitadel:zitadel:>=_3.0.0-rc.1,_<_3.4.3:*:*:*:*:*:*:*
|
| zitadel | zitadel | >= 2.55.0, < 2.71.18 | - | - |
cpe:2.3:a:zitadel:zitadel:>=_2.55.0,_<_2.71.18:*:*:*:*:*:*:*
|
| zitadel | zitadel | >= 2.54.3, <= 2.54.10 | - | - |
cpe:2.3:a:zitadel:zitadel:>=_2.54.3,_<=_2.54.10:*:*:*:*:*:*:*
|
| zitadel | zitadel | >= 2.53.6, <= 2.53.9 | - | - |
cpe:2.3:a:zitadel:zitadel:>=_2.53.6,_<=_2.53.9:*:*:*:*:*:*:*
|
| zitadel | zitadel | * | - | - |
cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
4.0 (cna)
HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-64103 |
2025-11-11 15:23:34 | 2025-11-11 07:40:49 |
| NVD | nvd_CVE-2025-64103 |
2025-11-11 15:01:07 | 2025-11-11 07:48:36 |
| CNNVD | cnnvd_CNNVD-202510-3961 |
2025-11-11 15:12:59 | 2025-11-11 08:00:20 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202510-3961
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 5 -> 6
- data_sources: ['cve'] -> ['cve', 'nvd']