CVE-2024-37905
Last modified
CVE-2024-37905 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to gain admin user privileges. EPSS estimates a 0.76% chance of exploitation in the next 30 days.
Description
authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to gain admin user privileges. A successful exploit of the issue will result in a user gaining full admin access to the Authentik application, including resetting user passwords and more. This issue has been patched in version(s) 2024.2.4, 2024.4.2 and 2024.6.0.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Goauthentik | Authentik | < 2024.2.4 |
| Goauthentik | Authentik | >= 2024.4.0, < 2024.4.3 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-37905?
How severe is CVE-2024-37905?
How do I fix CVE-2024-37905?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-3790Vulnerability in WBSAirback 21.02.04, which consists of a st…4.8
- CVE-2024-37900XWiki Platform is a generic wiki platform offering runtime s…4.6
- CVE-2024-37901XWiki Platform is a generic wiki platform offering runtime s…8.8
- CVE-2024-37902DeepJavaLibrary(DJL) is an Engine-Agnostic Deep Learning Fra…10
- CVE-2024-37903Mastodon is a self-hosted, federated microblogging platform.…8.2
- CVE-2024-37904Minder is an open source Software Supply Chain Security Plat…5.7
- CVE-2024-37906Admidio is a free, open source user management system for we…8.8
- CVE-2024-3791Vulnerability in WBSAirback 21.02.04, which consists of a st…4.8
- CVE-2024-37917Pexip Infinity before 35.0 has improper input validation tha…7.5
- CVE-2024-37918Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2024-37919Improper Neutralization of Input During Web Page Generation …5.9
- CVE-2024-3792Vulnerability in WBSAirback 21.02.04, which consists of a st…4.8
Are you affected by CVE-2024-37905?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
