VYPR
High severity7.2NVD Advisory· Published Nov 21, 2024· Updated Jun 17, 2026

CVE-2024-52287

CVE-2024-52287

Description

authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get a token from authentik with scopes that haven't been configured in authentik. authentik 2024.8.5 and 2024.10.3 fix this issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • authentik/authentikllm-fuzzy3 versions
    before 2024.8.5 and 2024.10.3+ 2 more
    • (no CPE)range: before 2024.8.5 and 2024.10.3
    • cpe:2.3:a:goauthentik:authentik:*:*:*:*:*:*:*:*range: <2024.8.5
    • (no CPE)range: < 2024.8.5
  • osv-coords
    Range: < 2024.8.5

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.