icon

We found results for “

CVE-2024-38371

Good to know:

icon

Date: June 28, 2024

authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when using the OAuth2 Device code flow. This could potentially allow users without the correct authorization to get OAuth tokens for an application and access it. This issue has been patched in version(s) 2024.6.0, 2024.2.4 and 2024.4.3.

Language: Python

Severity Score

Severity Score

Weakness Type (CWE)

Improper Access Control

CWE-284

Improper Authorization

CWE-285

Top Fix

icon

Upgrade Version

Upgrade to version version/2024.2.4,version/2024.4.3,version/2024.6.0

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): LOW
Availability (A): LOW

Do you need more information?

Contact Us