The Login UI did not sanitize input parameters. An attacker could create a malicious link, where injected code would be rendered as part of the login screen.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2024-2655" }
{ "custom_ranges": [ { "events": [ { "introduced": "0" }, { "fixed": "2.41.15" }, { "introduced": "2.42.0" }, { "fixed": "2.42.15" }, { "introduced": "2.43.0" }, { "fixed": "2.43.9" }, { "introduced": "2.44.0" }, { "fixed": "2.44.3" }, { "introduced": "2.45.0" }, { "fixed": "2.45.1" }, { "introduced": "2.46.0" }, { "fixed": "2.46.1" }, { "introduced": "2.47.0" }, { "fixed": "2.47.4" } ], "type": "ECOSYSTEM" } ], "imports": [ { "path": "github.com/zitadel/zitadel/internal/renderer" } ] }