Vulnerability Details CVE-2024-21637
Authentik is an open-source Identity Provider. Authentik is a vulnerable to a reflected Cross-Site Scripting vulnerability via JavaScript-URIs in OpenID Connect flows with `response_mode=form_post`. This relatively user could use the described attacks to perform a privilege escalation. This vulnerability has been patched in versions 2023.10.6 and 2023.8.6.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 32.9%
CVSS Severity
CVSS v3 Score 7.6
Products affected by CVE-2024-21637
-
cpe:2.3:a:goauthentik:authentik:2023.10.0
-
cpe:2.3:a:goauthentik:authentik:2023.10.1
-
cpe:2.3:a:goauthentik:authentik:2023.10.2
-
cpe:2.3:a:goauthentik:authentik:2023.10.3
-
cpe:2.3:a:goauthentik:authentik:2023.10.4
-
cpe:2.3:a:goauthentik:authentik:2023.10.5
-
cpe:2.3:a:goauthentik:authentik:2023.8.0
-
cpe:2.3:a:goauthentik:authentik:2023.8.1
-
cpe:2.3:a:goauthentik:authentik:2023.8.2
-
cpe:2.3:a:goauthentik:authentik:2023.8.3
-
cpe:2.3:a:goauthentik:authentik:2023.8.4
-
cpe:2.3:a:goauthentik:authentik:2023.8.5