- EPSS 0.36%
- Veröffentlicht 28.03.2025 14:42:39
- Zuletzt bearbeitet 21.08.2025 18:40:56
authentik is an open-source identity provider. Prior to versions 2024.12.4 and 2025.2.3, when authentik was configured to use the database for session storage (which is a non-default setting), deleting sessions via the Web Interface or the API would ...
CVE-2024-11623
- EPSS 0.29%
- Veröffentlicht 04.02.2025 14:15:30
- Zuletzt bearbeitet 21.08.2025 18:41:13
Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application icons. This action could only be performed by an authenticated admin user. The issue was fixed in 2024.10.4 release.
CVE-2024-52307
- EPSS 0.53%
- Veröffentlicht 21.11.2024 18:15:12
- Zuletzt bearbeitet 21.08.2025 19:19:21
authentik is an open-source identity provider. Due to the usage of a non-constant time comparison for the /-/metrics/ endpoint it was possible to brute-force the SECRET_KEY, which is used to authenticate the endpoint. The /-/metrics/ endpoint returns...
CVE-2024-52289
- EPSS 1.06%
- Veröffentlicht 21.11.2024 18:15:12
- Zuletzt bearbeitet 23.09.2025 19:15:38
authentik is an open-source identity provider. Redirect URIs in the OAuth2 provider in authentik are checked by RegEx comparison. When no Redirect URIs are configured in a provider, authentik will automatically use the first redirect_uri value receiv...
CVE-2024-52287
- EPSS 0.56%
- Veröffentlicht 21.11.2024 18:15:11
- Zuletzt bearbeitet 21.08.2025 19:21:32
authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get a token from authentik with scopes that haven't been configured in authentik. authentik 2024.8.5 and ...
CVE-2024-47077
- EPSS 0.42%
- Veröffentlicht 27.09.2024 16:15:06
- Zuletzt bearbeitet 21.08.2025 19:28:20
authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one application can be stolen by that application and used to impersonate the user against any other proxy provider. Also, a user can stea...
- EPSS 0.57%
- Veröffentlicht 27.09.2024 16:15:05
- Zuletzt bearbeitet 21.08.2025 19:28:44
authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024.8.3 and 2024.6.5 allows bypassing password login by adding X-Forwarded-For header with an unparsable IP address, e.g. `a`. This results in a possibil...
CVE-2024-42490
- EPSS 0.48%
- Veröffentlicht 22.08.2024 16:15:09
- Zuletzt bearbeitet 21.08.2025 19:29:02
authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. The main API endpoints affected by this are /api/v3/crypto/certificatekeypairs/<uuid>/view_certificate/, /api/...
CVE-2024-37905
- EPSS 0.76%
- Veröffentlicht 28.06.2024 18:15:04
- Zuletzt bearbeitet 21.08.2025 16:14:04
authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to gain admin user privileges. A successful exploit of the issue will result in a user gaining full admin...
CVE-2024-38371
- EPSS 0.59%
- Veröffentlicht 28.06.2024 18:15:04
- Zuletzt bearbeitet 21.08.2025 16:01:24
authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when using the OAuth2 Device code flow. This could potentially allow users without the correct authorization to get OAuth tokens for an app...