VYPR
Critical severity9.8NVD Advisory· Published Nov 21, 2024· Updated Jun 17, 2026

CVE-2024-52289

CVE-2024-52289

Description

authentik is an open-source identity provider. Redirect URIs in the OAuth2 provider in authentik are checked by RegEx comparison. When no Redirect URIs are configured in a provider, authentik will automatically use the first redirect_uri value received as an allowed redirect URI, without escaping characters that have a special meaning in RegEx. Similarly, the documentation did not take this into consideration either. Given a provider with the Redirect URIs set to https://foo.example.com, an attacker can register a domain fooaexample.com, and it will correctly pass validation. authentik 2024.8.5 and 2024.10.3 fix this issue. As a workaround, When configuring OAuth2 providers, make sure to escape any wildcard characters that are not intended to function as a wildcard, for example replace . with \..

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:goauthentik:authentik:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:goauthentik:authentik:*:*:*:*:*:*:*:*range: <2024.8.5
    • (no CPE)range: 2024.8.5 and 2024.10.3
    • (no CPE)range: < 2024.8.5
  • osv-coords
    Range: < 2024.8.5

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.