漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
authentik cross-provider token validation problems
Vulnerability Description
authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one application can be stolen by that application and used to impersonate the user against any other proxy provider. Also, a user can steal an access token they were legitimately issued for one application and use it to access another application that they aren't allowed to access. Anyone who has more than one proxy provider application with different trust domains or different access control is affected. Versions 2024.8.3 and 2024.6.5 fix the issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
授权机制不正确
Vulnerability Title
authentik 安全漏洞
Vulnerability Description
authentik是authentik开源的一个开源身份提供应用程序。 authentik存在安全漏洞,该漏洞源于用户可以窃取他们合法获得的访问令牌,用于访问他们没有权限访问的其他应用。
CVSS Information
N/A
Vulnerability Type
N/A