CVE-2024-42490
Last modified
CVE-2024-42490 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. The main API endpoints affected by this are /api/v3/crypto/certificatekeypairs/<uuid>/view_certificate/, /api/v3/crypto/certificatekeypairs/<uuid>/view_private_key/, and /api/v3/.../used_by/. Note that all of the affected API endpoints require the knowledge of the ID of an object, which especially for certificates is not accessible to an unprivileged user. Additionally the IDs for most objects are UUIDv4, meaning they are not easily guessable/enumerable. authentik 2024.4.4, 2024.6.4 and 2024.8.0 fix this issue.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Goauthentik | Authentik | < 2024.4.4 |
| Goauthentik | Authentik | >= 2024.6.0, < 2024.6.4 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-42490?
How severe is CVE-2024-42490?
How do I fix CVE-2024-42490?
Are you affected by CVE-2024-42490?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
