Unrated severityNVD Advisory· Published Jun 28, 2024· Updated Aug 2, 2024
Improper Access Control and Incorrect Authorization in github.com/goauthentik/authentik
CVE-2024-37905
Description
authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to gain admin user privileges. A successful exploit of the issue will result in a user gaining full admin access to the Authentik application, including resetting user passwords and more. This issue has been patched in version(s) 2024.2.4, 2024.4.2 and 2024.6.0.
Affected products
2- goauthentik/authentikv5Range: < 2024.6.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/goauthentik/authentik/releases/tag/version%2F2024.2.4mitrex_refsource_MISC
- github.com/goauthentik/authentik/releases/tag/version%2F2024.4.3mitrex_refsource_MISC
- github.com/goauthentik/authentik/releases/tag/version%2F2024.6.0mitrex_refsource_MISC
- github.com/goauthentik/authentik/security/advisories/GHSA-c78c-2r9w-p7x4mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.