{"id":"GO-2024-2655","summary":"XSS in github.com/zitadel/zitadel","details":"The Login UI did not sanitize input parameters. An attacker could create a malicious link, where injected code would be rendered as part of the login screen.","aliases":["CVE-2024-28855","GHSA-hfrg-4jwr-jfpj"],"modified":"2024-07-09T19:33:56Z","published":"2024-03-27T22:09:35Z","database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2024-2655"},"references":[{"type":"ADVISORY","url":"https://github.com/zitadel/zitadel/security/advisories/GHSA-hfrg-4jwr-jfpj"},{"type":"FIX","url":"https://github.com/zitadel/zitadel/commit/07ec2efa9dc62f7a6c3a58c112b2879d24bc3e3c"}],"affected":[{"package":{"name":"github.com/zitadel/zitadel","ecosystem":"Go","purl":"pkg:golang/github.com/zitadel/zitadel"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.80.0-v2.20.0.20240312162750-5908b97e7c22"}]}],"ecosystem_specific":{"custom_ranges":[{"events":[{"introduced":"0"},{"fixed":"2.41.15"},{"introduced":"2.42.0"},{"fixed":"2.42.15"},{"introduced":"2.43.0"},{"fixed":"2.43.9"},{"introduced":"2.44.0"},{"fixed":"2.44.3"},{"introduced":"2.45.0"},{"fixed":"2.45.1"},{"introduced":"2.46.0"},{"fixed":"2.46.1"},{"introduced":"2.47.0"},{"fixed":"2.47.4"}],"type":"ECOSYSTEM"}],"imports":[{"path":"github.com/zitadel/zitadel/internal/renderer"}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2024-2655.json"}}],"schema_version":"1.7.3","credits":[{"name":"Daniel Philipp (OWT) and Thomas Wickham (Synopsis)"}]}