CVE-2024-37905: Improper Access Control and Incorrect Authorization in github.com/goauthentik/authentik
authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to gain admin user privileges. A successful exploit of the issue will result in a user gaining full admin access to the Authentik application, including resetting user passwords and more. This issue has been patched in version(s) 2024.2.4, 2024.4.2 and 2024.6.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37905?
CVE-2024-37905 has a critical severity level as it allows unauthorized users to gain administrative privileges in Authentik.
How do I fix CVE-2024-37905?
To fix CVE-2024-37905, upgrade Authentik to version 2024.4.3 or later.
Which versions of Authentik are affected by CVE-2024-37905?
CVE-2024-37905 affects Authentik versions up to 2024.2.4 and between 2024.4.2 and 2024.6.0.
What is the impact of exploiting CVE-2024-37905?
Exploiting CVE-2024-37905 can grant an attacker full administrative access to the Authentik application.
Is there a way to prevent exploitation of CVE-2024-37905?
Prevent exploitation of CVE-2024-37905 by applying the latest security patches and restricting access to the API.