216.73.217.22

CVE-2024-38371

· Published 28/06/2024 18:15 · Modified 28/06/2024 18:15

Labels: CVE-2024-38371 2024-06-28CVE-2024-38371CWE-284[email protected]

Essential information

Published
28/06/2024 18:15
Modified
28/06/2024 18:15
Author
Creator
CVSS
8.6 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

CVSS metrics

Description

authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when using the OAuth2 Device code flow. This could potentially allow users without the correct authorization to get OAuth tokens for an application and access it. This issue has been patched in version(s) 2024.6.0, 2024.2.4 and 2024.4.3.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References