authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get a token from authentik with scopes that haven't been configured in authentik. authentik 2024.8.5 and 2024.10.3 fix this issue.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-11-21 18:15
Updated : 2025-08-21 19:21
NVD link : CVE-2024-52287
Mitre link : CVE-2024-52287
CVE.ORG link : CVE-2024-52287
JSON object : View
Products Affected
goauthentik
- authentik
CWE
CWE-285
Improper Authorization
