CVE-2023-46249
- EPSS 0.83%
- Veröffentlicht 31.10.2023 16:15:09
- Zuletzt bearbeitet 21.11.2024 08:28:09
authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the default admin user has been deleted, it is potentially possible for an attacker to set the password of the default admin user without any authentication...
CVE-2023-39522
- EPSS 0.78%
- Veröffentlicht 29.08.2023 18:15:08
- Zuletzt bearbeitet 21.11.2024 08:15:35
goauthentik is an open-source Identity Provider. In affected versions using a recovery flow with an identification stage an attacker is able to determine if a username exists. Only setups configured with a recovery flow are impacted by this. Anyone w...
CVE-2023-36456
- EPSS 0.42%
- Veröffentlicht 06.07.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 08:09:45
authentik is an open-source Identity Provider. Prior to versions 2023.4.3 and 2023.5.5, authentik does not verify the source of the X-Forwarded-For and X-Real-IP headers, both in the Python code and the go code. Only authentik setups that are directl...
CVE-2023-26481
- EPSS 0.17%
- Veröffentlicht 04.03.2023 01:15:10
- Zuletzt bearbeitet 21.11.2024 07:51:36
authentik is an open-source Identity Provider. Due to an insufficient access check, a recovery flow link that is created by an admin (or sent via email by an admin) can be used to set the password for any arbitrary user. This attack is only possible ...
CVE-2022-46172
- EPSS 0.26%
- Veröffentlicht 28.12.2022 07:15:07
- Zuletzt bearbeitet 21.11.2024 07:30:15
authentik is an open-source Identity provider focused on flexibility and versatility. In versions prior to 2022.10.4, and 2022.11.4, any authenticated user can create an arbitrary number of accounts through the default flows. This would circumvent an...
CVE-2022-23555
- EPSS 0.16%
- Veröffentlicht 28.12.2022 01:15:10
- Zuletzt bearbeitet 21.11.2024 06:48:48
authentik is an open-source Identity Provider focused on flexibility and versatility. Versions prior to 2022.11.4 and 2022.10.4 are vulnerable to Improper Authentication. Token reuse in invitation URLs leads to access control bypass via the use of a ...
CVE-2022-46145
- EPSS 2.4%
- Veröffentlicht 02.12.2022 18:15:12
- Zuletzt bearbeitet 21.11.2024 07:30:11
authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized user creation and potential account takeover. With the default flows, unauthenticated users can create new accounts in authentik. ...