An open API service providing package, version and dependency metadata of many open source software ecosystems and registries.

Top 4.8% on proxy.golang.org
Top 1.6% forks on proxy.golang.org

proxy.golang.org : github.com/zitadel/zitadel

ZITADEL - The best of Auth0 and Keycloak combined. Built for the serverless era.

Registry - Source - Documentation - JSON
purl: pkg:golang/github.com/zitadel/zitadel
Keywords: 2fa , authentication , authorization , fido2 , identity , login , mfa , oauth2 , oidc , openid-connect , passkeys , saml , sso , user
License: Apache-2.0
Latest release: over 2 years ago
First release: about 5 years ago
Namespace: github.com/zitadel
Stars: 3,266 on GitHub
Forks: 177 on GitHub
Docker dependents: 3
Docker downloads: 157
See more repository details: repos.ecosyste.ms
Last synced: 5 days ago

High
GSA_kwCzR0hTQS1nNHI4LW1wN2ctODVmcc4ABHiR
ZITADEL Allows IdP Intent Token Reuse
Ecosystems: go
Packages: github.com/zitadel/zitadel
Source: github
Published: 26 days ago
High
GSA_kwCzR0hTQS03aDhtLXZyeHgtdnI0bc4AA2_V
ZITADEL race condition in lockout policy execution
Ecosystems: go
Packages: github.com/zitadel/zitadel
Source: github
Published: over 1 year ago
Moderate
GSA_kwCzR0hTQS12NjgzLXJjeHgtdnBmZs4AA2X6
ZITADEL's password reset does not respect the "Ignoring unknown usernames" setting
Ecosystems: go
Packages: github.com/zitadel/zitadel
Source: github
Published: over 1 year ago
High
GSA_kwCzR0hTQS1ocjV3LWN3d3EtMnY0bc4AA6as
ZITADEL's Improper Content-Type Validation Leads to Account Takeover via Stored XSS + CSP Bypass
Ecosystems: go
Packages: github.com/zitadel/zitadel
Source: github
Published: about 1 year ago
High
GSA_kwCzR0hTQS1ncDhnLWY0MmYtOTVxMs4AA6ar
ZITADEL's actions can overload reserved claims
Ecosystems: go
Packages: github.com/zitadel/zitadel
Source: github
Published: about 1 year ago
High
GSA_kwCzR0hTQS1tcTR4LXIydzMtajdtcs4AA54b
Account Takeover via Session Fixation in Zitadel [Bypassing MFA]
Ecosystems: go
Packages: github.com/zitadel/zitadel
Source: github
Published: about 1 year ago
High
GSA_kwCzR0hTQS0zcm13LTc2bTYtNGdqY84ABAq8
User Registration Bypass in Zitadel
Ecosystems: go
Packages: github.com/zitadel/zitadel
Source: github
Published: 7 months ago
Moderate
GSA_kwCzR0hTQS1jdnc5LWM1N2gtMzM5N84AA9m1
ZITADEL Vulnerable to Session Information Leakage
Ecosystems: go
Packages: github.com/zitadel/zitadel
Source: github
Published: 11 months ago
Moderate
GSA_kwCzR0hTQS02Y2Y1LXc5aDMtNHJxds4ABAq7
Denied Host Validation Bypass in Zitadel Actions
Ecosystems: go
Packages: github.com/zitadel/zitadel
Source: github
Published: 7 months ago
High
GSA_kwCzR0hTQS1jOGZqLTRwbTgtbXAyY84AAui6
Broken Authorization in ZITADEL Actions
Ecosystems: go
Packages: github.com/zitadel/zitadel
Source: github
Published: almost 3 years ago
High
GSA_kwCzR0hTQS1oZnJnLTRqd3ItamZwas4AA6Gn
Improper HTML sanitization in ZITADEL
Ecosystems: go
Packages: github.com/zitadel/zitadel
Source: github
Published: about 1 year ago
Moderate
GSA_kwCzR0hTQS01Njd2LTZobWctNnFnN84AA-TF
ZITADEL "ignoring unknown usernames" vulnerability
Ecosystems: go
Packages: github.com/zitadel/zitadel
Source: github
Published: 10 months ago
Critical
GSA_kwCzR0hTQS1mM2doLTUyOXctdjMyeM4ABFE2
IDOR Vulnerabilities in ZITADEL's Admin API that Primarily Impact LDAP Configurations
Ecosystems: go
Packages: github.com/zitadel/zitadel, github.com/zitadel/zitadel/v2
Source: github
Published: 3 months ago
Moderate
GSA_kwCzR0hTQS1xNXFqLXgyaDUtMzk0Nc4AA7eF
Zitadel exposing internal database user name and host information
Ecosystems: go
Packages: github.com/zitadel/zitadel
Source: github
Published: about 1 year ago
High
GSA_kwCzR0hTQS0yd21qLTQ2cmotcW0yd84AA3az
ZITADEL Account Takeover via Malicious Host Header Injection
Ecosystems: go
Packages: github.com/zitadel/zitadel
Source: github
Published: over 1 year ago
High
GSA_kwCzR0hTQS03ajdqLTY2Y3YtbTIzOc4AA7UD
ZITADEL's Improper Lockout Mechanism Leads to MFA Bypass
Ecosystems: go
Packages: github.com/zitadel/zitadel
Source: github
Published: about 1 year ago
Moderate
GSA_kwCzR0hTQS02cnJyLTc4eHAtNWpwOM4AAw6R
Zitadel RefreshToken invalidation vulnerability
Ecosystems: go
Packages: github.com/zitadel/zitadel
Source: github
Published: over 2 years ago
High
GSA_kwCzR0hTQS05M200LW1mcGctYzN4Zs4ABIbp
ZITADEL Allows Account Takeover via Malicious X-Forwarded-Proto Header Injection
Ecosystems: go
Packages: github.com/zitadel/zitadel/v2, github.com/zitadel/zitadel
Source: github
Published: 4 days ago
Moderate
GSA_kwCzR0hTQS12MzMzLTdoMnAtNWZods4AA-TE
ZITADEL has improper HTML sanitization in emails and Console UI
Ecosystems: go
Packages: github.com/zitadel/zitadel
Source: github
Published: 10 months ago