漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
authentik has Insufficient Authorization for several API endpoints
Vulnerability Description
authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. The main API endpoints affected by this are /api/v3/crypto/certificatekeypairs/<uuid>/view_certificate/, /api/v3/crypto/certificatekeypairs/<uuid>/view_private_key/, and /api/v3/.../used_by/. Note that all of the affected API endpoints require the knowledge of the ID of an object, which especially for certificates is not accessible to an unprivileged user. Additionally the IDs for most objects are UUIDv4, meaning they are not easily guessable/enumerable. authentik 2024.4.4, 2024.6.4 and 2024.8.0 fix this issue.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
Vulnerability Type
授权机制不恰当
Vulnerability Title
authentik 安全漏洞
Vulnerability Description
authentik是authentik开源的一个开源身份提供应用程序。 authentik 2024.6.4之前版本和2024.4.4之前版本存在安全漏洞,该漏洞源于用户无需正确的身份验证/授权即可访问多个API端点。
CVSS Information
N/A
Vulnerability Type
N/A