CVE-2024-37905

CVSS V2 None CVSS V3 None
Description
authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to gain admin user privileges. A successful exploit of the issue will result in a user gaining full admin access to the Authentik application, including resetting user passwords and more. This issue has been patched in version(s) 2024.2.4, 2024.4.2 and 2024.6.0.
Overview
  • CVE ID
  • CVE-2024-37905
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-06-28T17:09:24.090Z
  • Last Modified Date
  • 2024-06-28T17:09:24.090Z
History
Created Old Value New Value Data Type Notes
2024-06-29 13:02:52 Added to TrackCVE