CVE-2024-21637
XSS in Authentik via JavaScript-URI as Redirect URI and form_post Response Mode
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Authentik is an open-source Identity Provider. Authentik is a vulnerable to a reflected Cross-Site Scripting vulnerability via JavaScript-URIs in OpenID Connect flows with `response_mode=form_post`. This relatively user could use the described attacks to perform a privilege escalation. This vulnerability has been patched in versions 2023.10.6 and 2023.8.6.
Authentik es un proveedor de identidades de código abierto. Authentik es afectado por una vulnerabilidad de cross site scripting reflejada a través de URI de JavaScript en flujos de OpenID Connect con `response_mode=form_post`. Este relativamente usuario podría utilizar los ataques descritos para realizar una escalada de privilegios. Esta vulnerabilidad ha sido parcheada en las versiones 2023.10.6 y 2023.8.6.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-12-29 CVE Reserved
- 2024-01-11 CVE Published
- 2024-08-01 CVE Updated
- 2025-01-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/goauthentik/authentik/security/advisories/GHSA-rjpr-7w8c-gv3j | Mitigation |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/goauthentik/authentik/releases/tag/version%2F2023.10.6 | 2024-01-16 | |
https://github.com/goauthentik/authentik/releases/tag/version%2F2023.8.6 | 2024-01-16 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Goauthentik Search vendor "Goauthentik" | Authentik Search vendor "Goauthentik" for product "Authentik" | >= 2023.8.0 < 2023.8.6 Search vendor "Goauthentik" for product "Authentik" and version " >= 2023.8.0 < 2023.8.6" | - |
Affected
| ||||||
Goauthentik Search vendor "Goauthentik" | Authentik Search vendor "Goauthentik" for product "Authentik" | >= 2023.10.0 < 2023.10.6 Search vendor "Goauthentik" for product "Authentik" and version " >= 2023.10.0 < 2023.10.6" | - |
Affected
|