Session Management Flaw in Authentik Identity Provider
CVE-2025-29928

8HIGH

Key Information:

Status
Vendor
CVE Published:
28 March 2025

What is CVE-2025-29928?

The Authentik identity provider has a significant issue affecting its session management functionalities. When configured to use the database for session storage, deleting sessions via the web interface or API does not effectively revoke the session. Consequently, session holders maintain unauthorized access, leading to potential unauthorized actions within the platform. Users are advised to switch to cache-based session storage as an interim measure until they can upgrade to versions 2024.12.4 or 2025.2.3, although this will necessitate session deletion and user re-authentication.

Affected Version(s)

authentik < 2024.12.4 < 2024.12.4

authentik < 2025.2.3 < 2025.2.3

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.