CVE-2024-11623: Stored XSS in authentik
Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application icons. This action could only be performed by an authenticated admin user. The issue was fixed in 2024.10.4 release.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11623?
CVE-2024-11623 is classified as a medium severity vulnerability due to its potential for Stored XSS attacks.
How do I fix CVE-2024-11623?
To resolve CVE-2024-11623, upgrade to the Authentik version 2024.10.4 or later.
Who is affected by CVE-2024-11623?
CVE-2024-11623 affects Authentik versions prior to 2024.10.4, specifically when admin users upload crafted SVG files.
What type of attack is associated with CVE-2024-11623?
CVE-2024-11623 is associated with Stored XSS attacks, which can be executed when malicious SVG files are uploaded.
Can any user exploit CVE-2024-11623?
No, only authenticated admin users can exploit CVE-2024-11623 by uploading specially crafted SVG files.