Denied Host Validation Bypass in Zitadel Actions in github.com/zitadel/zitadel.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/zitadel/zitadel before v2.58.7, from v2.59.0 before v2.59.5, from v2.60.0 before v2.60.4, from v2.61.0 before v2.61.4, from v2.62.0 before v2.62.8, from v2.63.0 before v2.63.6, from v2.64.0 before v2.64.1.
{ "review_status": "UNREVIEWED", "url": "https://pkg.go.dev/vuln/GO-2024-3216" }
{ "custom_ranges": [ { "events": [ { "introduced": "0" }, { "fixed": "2.58.7" }, { "introduced": "2.59.0" }, { "fixed": "2.59.5" }, { "introduced": "2.60.0" }, { "fixed": "2.60.4" }, { "introduced": "2.61.0" }, { "fixed": "2.61.4" }, { "introduced": "2.62.0" }, { "fixed": "2.62.8" }, { "introduced": "2.63.0" }, { "fixed": "2.63.6" }, { "introduced": "2.64.0" }, { "fixed": "2.64.1" } ], "type": "ECOSYSTEM" } ] }