ZITADEL Patches (T)OTP Check Lockout Mechanism in Version 2.50.0
CVE-2024-32868
8.1HIGH
What is CVE-2024-32868?
ZITADEL users may experience vulnerabilities related to Time-based One-Time Passwords (TOTP) and One-Time Passwords (OTP) sent via SMS and Email. Although administrators can set a lockout policy for failed password attempts, a similar mechanism was previously absent for TOTP checks. This oversight in security can lead to unauthorized access if exploited. This issue has been addressed and patched starting from version 2.50.0, enhancing the overall security framework for password verification processes.
Affected Version(s)
zitadel < 2.50.0
