Denied Host Validation Bypass in Zitadel Actions in github.com/zitadel/zitadel.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/zitadel/zitadel before v2.58.7, from v2.59.0 before v2.59.5, from v2.60.0 before v2.60.4, from v2.61.0 before v2.61.4, from v2.62.0 before v2.62.8, from v2.63.0 before v2.63.6, from v2.64.0 before v2.64.1.
{
"review_status": "UNREVIEWED",
"url": "https://pkg.go.dev/vuln/GO-2024-3216"
}{
"custom_ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "2.58.7"
},
{
"introduced": "2.59.0"
},
{
"fixed": "2.59.5"
},
{
"introduced": "2.60.0"
},
{
"fixed": "2.60.4"
},
{
"introduced": "2.61.0"
},
{
"fixed": "2.61.4"
},
{
"introduced": "2.62.0"
},
{
"fixed": "2.62.8"
},
{
"introduced": "2.63.0"
},
{
"fixed": "2.63.6"
},
{
"introduced": "2.64.0"
},
{
"fixed": "2.64.1"
}
]
}
]
}