VYPR

authentik

by authentik

Source repositories

CVEs (45)

  • CVE-2023-48228HigNov 21, 2023
    risk 0.00cvss 7.5epss 0.01

    authentik is an open-source identity provider. When initialising a oauth2 flow with a `code_challenge` and `code_method` (thus requesting PKCE), the single sign-on provider (authentik) must check if there is a matching and existing `code_verifier` during the token step. Prior to…

  • CVE-2023-46249CriOct 31, 2023
    risk 0.00cvss 9.6epss 0.01

    authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the default admin user has been deleted, it is potentially possible for an attacker to set the password of the default admin user without any authentication. authentik uses a blueprint…

  • CVE-2023-36456HigJul 6, 2023
    risk 0.00cvss 8.3epss 0.01

    authentik is an open-source Identity Provider. Prior to versions 2023.4.3 and 2023.5.5, authentik does not verify the source of the X-Forwarded-For and X-Real-IP headers, both in the Python code and the go code. Only authentik setups that are directly accessible by users without…

  • CVE-2008-1175Mar 6, 2008
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in AuthentiX 6.3b1 Trial allows remote attackers to inject arbitrary web script or HTML via the username parameter to aspAdmin/deleteUser.asp, a different vector than CVE-2008-1174. NOTE: the provenance of this information is unknown;…

  • CVE-2000-1133Jan 9, 2001
    risk 0.00cvss epss 0.02

    Authentix Authentix100 allows remote attackers to bypass authentication by inserting a . (dot) into the URL for a protected directory.

Page 3 of 3