CVE-2024-52289
- EPSS 0.3%
- Veröffentlicht 21.11.2024 18:15:12
- Zuletzt bearbeitet 23.09.2025 19:15:38
authentik is an open-source identity provider. Redirect URIs in the OAuth2 provider in authentik are checked by RegEx comparison. When no Redirect URIs are configured in a provider, authentik will automatically use the first redirect_uri value receiv...
CVE-2024-52287
- EPSS 0.18%
- Veröffentlicht 21.11.2024 18:15:11
- Zuletzt bearbeitet 21.08.2025 19:21:32
authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get a token from authentik with scopes that haven't been configured in authentik. authentik 2024.8.5 and ...
CVE-2024-47077
- EPSS 0.28%
- Veröffentlicht 27.09.2024 16:15:06
- Zuletzt bearbeitet 21.08.2025 19:28:20
authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one application can be stolen by that application and used to impersonate the user against any other proxy provider. Also, a user can stea...
- EPSS 0.15%
- Veröffentlicht 27.09.2024 16:15:05
- Zuletzt bearbeitet 21.08.2025 19:28:44
authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024.8.3 and 2024.6.5 allows bypassing password login by adding X-Forwarded-For header with an unparsable IP address, e.g. `a`. This results in a possibil...
CVE-2024-42490
- EPSS 1.46%
- Veröffentlicht 22.08.2024 16:15:09
- Zuletzt bearbeitet 21.08.2025 19:29:02
authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. The main API endpoints affected by this are /api/v3/crypto/certificatekeypairs/<uuid>/view_certificate/, /api/...
CVE-2024-38371
- EPSS 0.73%
- Veröffentlicht 28.06.2024 18:15:04
- Zuletzt bearbeitet 21.08.2025 16:01:24
authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when using the OAuth2 Device code flow. This could potentially allow users without the correct authorization to get OAuth tokens for an app...
CVE-2024-37905
- EPSS 3.69%
- Veröffentlicht 28.06.2024 18:15:04
- Zuletzt bearbeitet 21.08.2025 16:14:04
authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to gain admin user privileges. A successful exploit of the issue will result in a user gaining full admin...
CVE-2024-23647
- EPSS 0.07%
- Veröffentlicht 30.01.2024 17:15:10
- Zuletzt bearbeitet 21.11.2024 08:58:05
Authentik is an open-source Identity Provider. There is a bug in our implementation of PKCE that allows an attacker to circumvent the protection that PKCE offers. PKCE adds the code_challenge parameter to the authorization request and adds the code_v...
CVE-2024-21637
- EPSS 0.16%
- Veröffentlicht 11.01.2024 06:15:43
- Zuletzt bearbeitet 21.11.2024 08:54:46
Authentik is an open-source Identity Provider. Authentik is a vulnerable to a reflected Cross-Site Scripting vulnerability via JavaScript-URIs in OpenID Connect flows with `response_mode=form_post`. This relatively user could use the described attack...
CVE-2023-48228
- EPSS 0.88%
- Veröffentlicht 21.11.2023 21:15:08
- Zuletzt bearbeitet 21.11.2024 08:31:15
authentik is an open-source identity provider. When initialising a oauth2 flow with a `code_challenge` and `code_method` (thus requesting PKCE), the single sign-on provider (authentik) must check if there is a matching and existing `code_verifier` du...