CVE-2024-37905
Improper Access Control and Incorrect Authorization in github.com/goauthentik/authentik
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to gain admin user privileges. A successful exploit of the issue will result in a user gaining full admin access to the Authentik application, including resetting user passwords and more. This issue has been patched in version(s) 2024.2.4, 2024.4.2 and 2024.6.0.
authentik es un proveedor de identidades de código abierto que enfatiza la flexibilidad y la versatilidad. El mecanismo Authentik API-Access-Token se puede explotar para obtener privilegios de usuario administrador. Una explotación exitosa del problema dará como resultado que un usuario obtenga acceso de administrador completo a la aplicación Authentik, incluido el restablecimiento de contraseñas de usuario y más. Este problema se solucionó en las versiones 2024.2.4, 2024.4.2 y 2024.6.0.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-06-10 CVE Reserved
- 2024-06-28 CVE Published
- 2024-06-29 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
- CWE-863: Incorrect Authorization
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/goauthentik/authentik/releases/tag/version%2F2024.2.4 | X_refsource_misc | |
https://github.com/goauthentik/authentik/releases/tag/version%2F2024.4.3 | X_refsource_misc | |
https://github.com/goauthentik/authentik/releases/tag/version%2F2024.6.0 | X_refsource_misc | |
https://github.com/goauthentik/authentik/security/advisories/GHSA-c78c-2r9w-p7x4 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Goauthentik Search vendor "Goauthentik" | Authentik Search vendor "Goauthentik" for product "Authentik" | * | - |
Affected
|