authentik是authentik开源的一个开源身份提供应用程序。 authentik存在授权问题漏洞,该漏洞源于当使用client_credentials或device_codeOAuth授权时,导致攻击者会从Authentik获取一个令牌。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| goauthentik | authentik | < 2024.8.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-52307 | authentik allows a timing attack due to missing constant time comparison for metrics view | |
| CVE-2024-52289 | authentik has an insecure default configuration for OAuth2 Redirect URIs |
No comments yet