Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
authentik has Insufficient Authorization for several API endpoints
Vulnerability Description
authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. The main API endpoints affected by this are /api/v3/crypto/certificatekeypairs/<uuid>/view_certificate/, /api/v3/crypto/certificatekeypairs/<uuid>/view_private_key/, and /api/v3/.../used_by/. Note that all of the affected API endpoints require the knowledge of the ID of an object, which especially for certificates is not accessible to an unprivileged user. Additionally the IDs for most objects are UUIDv4, meaning they are not easily guessable/enumerable. authentik 2024.4.4, 2024.6.4 and 2024.8.0 fix this issue.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
Vulnerability Type
授权机制不恰当
Vulnerability Title
authentik 安全漏洞
Vulnerability Description
authentik是authentik开源的一个开源身份提供应用程序。 authentik 2024.6.4之前版本和2024.4.4之前版本存在安全漏洞,该漏洞源于用户无需正确的身份验证/授权即可访问多个API端点。
CVSS Information
N/A
Vulnerability Type
N/A