CVE-2024-47077: authentik cross-provider token validation problems

Published Sep 27, 2024
·
Updated

authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one application can be stolen by that application and used to impersonate the user against any other proxy provider. Also, a user can steal an access token they were legitimately issued for one application and use it to access another application that they aren't allowed to access. Anyone who has more than one proxy provider application with different trust domains or different access control is affected. Versions 2024.8.3 and 2024.6.5 fix the issue.

Affected Software

3 affected components
Authentik Authentik<2024.6.5, <2024.8.3
goauthentik Authentik<2024.6.5
goauthentik Authentik>=2024.8.0<2024.8.3

Event History

Sep 27, 2024
CVE Published
via MITRE·03:26 PM
Data Sourced
via MITRE·03:26 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-47077?

CVE-2024-47077 has been assessed as a high severity vulnerability due to its potential to allow unauthorized access through stolen access tokens.

2

How do I fix CVE-2024-47077?

To mitigate CVE-2024-47077, upgrade your authentik version to 2024.8.3 or later, or 2024.6.5 or later.

3

What applications are affected by CVE-2024-47077?

CVE-2024-47077 affects versions of authentik prior to 2024.8.3 and 2024.6.5.

4

Can users exploit CVE-2024-47077 themselves?

Yes, users can exploit CVE-2024-47077 to steal access tokens they were legitimately issued.

5

Why is CVE-2024-47077 a risk for multi-application environments?

CVE-2024-47077 poses a risk in multi-application environments as stolen access tokens can be used to impersonate users across different proxy providers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203