CVE-2024-42490
Last modified
CVE-2024-42490 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. The main API endpoints affected by this are /api/v3/crypto/certificatekeypairs/<uuid>/view_certificate/, /api/v3/crypto/certificatekeypairs/<uuid>/view_private_key/, and /api/v3/.../used_by/. Note that all of the affected API endpoints require the knowledge of the ID of an object, which especially for certificates is not accessible to an unprivileged user. Additionally the IDs for most objects are UUIDv4, meaning they are not easily guessable/enumerable. authentik 2024.4.4, 2024.6.4 and 2024.8.0 fix this issue.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Goauthentik | Authentik | < 2024.4.4 |
| Goauthentik | Authentik | >= 2024.6.0, < 2024.6.4 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-42490?
How severe is CVE-2024-42490?
How do I fix CVE-2024-42490?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-42485Filament Excel enables excel export for Filament admin resou…7.5
- CVE-2024-42486Cilium is a networking, observability, and security solution…7.2
- CVE-2024-42487Cilium is a networking, observability, and security solution…4.3
- CVE-2024-42488Cilium is a networking, observability, and security solution…6.8
- CVE-2024-42489Pro Macros provides XWiki rendering macros. Missing escaping…8.8
- CVE-2024-4249A vulnerability was found in Tenda i21 1.0.0.14(4656). It ha…8.8
- CVE-2024-42491Asterisk is an open-source private branch exchange (PBX). Pr…5.7
- CVE-2024-42492Uncontrolled search path element in some BIOS and System Fir…6.7
- CVE-2024-42493Dorsett Controls InfoScan is vulnerable due to a leak of pos…5.3
- CVE-2024-42494Ruijie Reyee OS versions 2.206.x up to but not including 2.3…7.5
- CVE-2024-42495Credentials to access device configuration were transmitted …7.5
- CVE-2024-42496Smart-tab Android app installed April 2023 or earlier contai…2.4
Are you affected by CVE-2024-42490?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
