CVE-2024-21637: XSS in Authentik via JavaScript-URI as Redirect URI and form_post Response Mode
Authentik is an open-source Identity Provider. Authentik is a vulnerable to a reflected Cross-Site Scripting vulnerability via JavaScript-URIs in OpenID Connect flows with responsemode=formpost. This relatively user could use the described attacks to perform a privilege escalation. This vulnerability has been patched in versions 2023.10.6 and 2023.8.6.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
authentikto a version that resolves this vulnerability.Fixed in 2023.10.6 - Upgrade
Upgrade
authentikto a version that resolves this vulnerability.Fixed in 2023.8.6
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21637?
CVE-2024-21637 has been classified with a high severity due to its potential for reflected Cross-Site Scripting and privilege escalation.
How do I fix CVE-2024-21637?
To fix CVE-2024-21637, you should upgrade your Authentik installation to version 2023.10.6 or later, or 2023.8.6 or later.
Who is affected by CVE-2024-21637?
CVE-2024-21637 affects Authentik versions from 2023.8.0 to 2023.8.6 and from 2023.10.0 to 2023.10.6.
What type of vulnerability is CVE-2024-21637?
CVE-2024-21637 is a reflected Cross-Site Scripting vulnerability that can be exploited through OpenID Connect flows.
What could an attacker do with CVE-2024-21637?
An attacker could leverage CVE-2024-21637 to perform privilege escalation by executing malicious JavaScript code.