Zitadel, Authentication Bypass via Brute-Force, CVE-2024-XXXX (Critical)

Listen to this Post

The vulnerability in Zitadel’s authentication API endpoints allows an attacker to perform unlimited online brute-force attacks against One-Time Passwords (OTP), Time-Based OTPs (TOTP), and user passwords. The flaw existed because the built-in lockout mechanism, designed to block an account after a certain number of failed attempts, was not enabled by default. Furthermore, this mitigation was inconsistently applied and was entirely missing from newer resource-based APIs. Consequently, an attacker could systematically guess authentication credentials without triggering an account lock. To exploit this, an attacker would target login or multi-factor authentication (MFA) endpoints, sending a high volume of requests with different password or code combinations. The lack of a mandatory lockout policy and the absence of sufficient rate-limiting on these critical paths made the attack feasible, allowing for user impersonation if the correct credentials were discovered through brute-force.
Platform: Zitadel
Version: 2.x-4.x
Vulnerability: Brute-force
Severity: Critical
date: 2024-10-30

Prediction: Patch 2024-11-13

What Undercode Say:

hydra -l [email protected] -P password_list.txt zitadel.example.com http-post-form "/oauth/v2/token:grant_type=password&username=^USER^&password=^PASS^:invalid_grant"
for code in {000000..999999}; do
curl -X POST "https://zitadel.instance/oauth/v2/token" -d "grant_type=password&username=target&password=guess&totp=$code"
done

How Exploit:

Attacker targets /oauth/v2/token or resource API endpoints. Sends repeated authentication requests with different passwords or TOTP codes. Bypasses optional lockout policy that is disabled by default. Exploits missing lockout enforcement in newer resource-based APIs.

Protection from this CVE

Upgrade to Zitadel v2.71.18, v3.4.3, or v4.6.0. Enable the “Password maximum attempts” lockout policy. Implement strict rate limiting. The patch enforces lockout policies universally and introduces a default “tar pit” delaying responses after failed attempts.

Impact:

Account Takeover

User Impersonation

Data Breach

Bypassed MFA

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top