{"id":"GHSA-qr2h-7pwm-h393","summary":"ZITADEL's Service Users Deactivation not Working ","details":"### Impact\nZITADEL's user account deactivation mechanism did not work correctly with service accounts. Deactivated service accounts retained the ability to request tokens, which could lead to unauthorized access to applications and resources.\n\n### Patches\n\n2.x versions are fixed on \u003e= [2.62.1](https://github.com/zitadel/zitadel/releases/tag/v2.62.1)\n2.61.x versions are fixed on \u003e= [2.61.1](https://github.com/zitadel/zitadel/releases/tag/v2.61.1)\n2.60.x versions are fixed on \u003e= [2.60.2](https://github.com/zitadel/zitadel/releases/tag/v2.60.2)\n2.59.x versions are fixed on \u003e= [2.59.3](https://github.com/zitadel/zitadel/releases/tag/v2.59.3)\n2.58.x versions are fixed on \u003e= [2.58.5](https://github.com/zitadel/zitadel/releases/tag/v2.58.5)\n2.57.x versions are fixed on \u003e= [2.57.5](https://github.com/zitadel/zitadel/releases/tag/v2.57.5)\n2.56.x versions are fixed on \u003e= [2.56.6](https://github.com/zitadel/zitadel/releases/tag/v2.56.6)\n2.55.x versions are fixed on \u003e= [2.55.8](https://github.com/zitadel/zitadel/releases/tag/v2.55.8)\n2.54.x versions are fixed on \u003e= [2.54.10](https://github.com/zitadel/zitadel/releases/tag/v2.54.10)\n\n### Workarounds\nInstead of deactivating the service account, consider creating new credentials and replacing the old ones wherever they are used. This effectively prevents the deactivated service account from being utilized.\n\n- Revoke all existing authentication keys associated with the service account\n- Rotate the service account's password\n\n### Questions\nIf you have any questions or comments about this advisory, please email us at \n\n[security@zitadel.com](mailto:security@zitadel.com)","aliases":["CVE-2024-47000","GO-2024-3139"],"modified":"2024-09-26T18:57:34.316232Z","published":"2024-09-19T16:08:01Z","database_specific":{"nvd_published_at":"2024-09-20T00:15:03Z","cwe_ids":["CWE-269","CWE-672"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-09-19T16:08:01Z"},"references":[{"type":"WEB","url":"https://github.com/zitadel/zitadel/security/advisories/GHSA-qr2h-7pwm-h393"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47000"},{"type":"PACKAGE","url":"https://github.com/zitadel/zitadel"}],"affected":[{"package":{"name":"github.com/zitadel/zitadel/v2","ecosystem":"Go","purl":"pkg:golang/github.com/zitadel/zitadel/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.62.0"},{"fixed":"2.62.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-qr2h-7pwm-h393/GHSA-qr2h-7pwm-h393.json"}},{"package":{"name":"github.com/zitadel/zitadel/v2","ecosystem":"Go","purl":"pkg:golang/github.com/zitadel/zitadel/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.61.0"},{"fixed":"2.61.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-qr2h-7pwm-h393/GHSA-qr2h-7pwm-h393.json"}},{"package":{"name":"github.com/zitadel/zitadel/v2","ecosystem":"Go","purl":"pkg:golang/github.com/zitadel/zitadel/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.60.0"},{"fixed":"2.60.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-qr2h-7pwm-h393/GHSA-qr2h-7pwm-h393.json"}},{"package":{"name":"github.com/zitadel/zitadel/v2","ecosystem":"Go","purl":"pkg:golang/github.com/zitadel/zitadel/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.59.0"},{"fixed":"2.59.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-qr2h-7pwm-h393/GHSA-qr2h-7pwm-h393.json"}},{"package":{"name":"github.com/zitadel/zitadel/v2","ecosystem":"Go","purl":"pkg:golang/github.com/zitadel/zitadel/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.58.0"},{"fixed":"2.58.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-qr2h-7pwm-h393/GHSA-qr2h-7pwm-h393.json"}},{"package":{"name":"github.com/zitadel/zitadel/v2","ecosystem":"Go","purl":"pkg:golang/github.com/zitadel/zitadel/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.57.0"},{"fixed":"2.57.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-qr2h-7pwm-h393/GHSA-qr2h-7pwm-h393.json"}},{"package":{"name":"github.com/zitadel/zitadel/v2","ecosystem":"Go","purl":"pkg:golang/github.com/zitadel/zitadel/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.56.0"},{"fixed":"2.56.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-qr2h-7pwm-h393/GHSA-qr2h-7pwm-h393.json"}},{"package":{"name":"github.com/zitadel/zitadel/v2","ecosystem":"Go","purl":"pkg:golang/github.com/zitadel/zitadel/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.55.0"},{"fixed":"2.55.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-qr2h-7pwm-h393/GHSA-qr2h-7pwm-h393.json"}},{"package":{"name":"github.com/zitadel/zitadel/v2","ecosystem":"Go","purl":"pkg:golang/github.com/zitadel/zitadel/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.54.10"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-qr2h-7pwm-h393/GHSA-qr2h-7pwm-h393.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}