Authentik API-Access-Token Vulnerability Allows for Admin User Privileges Exploit
CVE-2024-37905
What is CVE-2024-37905?
The Authentik Identity Provider, an open-source solution for identity management, has a critical vulnerability within its API-Access-Token mechanism. This vulnerability can be exploited by malicious actors to gain unauthorized admin access, allowing them to manipulate user accounts, reset passwords, and potentially disrupt service integrity. Users and administrators are advised to update to patched versions 2024.2.4, 2024.4.2, or 2024.6.0 to mitigate this unauthorized access risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
authentik < 2024.6.0 < 2024.6.0
authentik < 2024.4.2 < 2024.4.2
authentik < 2024.2.4 < 2024.2.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
