CVE-2024-52287: authentik performs insufficient validation of OAuth scopes
authentik is an open-source identity provider. When using the clientcredentials or devicecode OAuth grants, it was possible for an attacker to get a token from authentik with scopes that haven't been configured in authentik. authentik 2024.8.5 and 2024.10.3 fix this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52287?
CVE-2024-52287 is considered a medium severity vulnerability due to the potential unauthorized access to tokens.
How do I fix CVE-2024-52287?
To fix CVE-2024-52287, update authentik to version 2024.8.5 or 2024.10.3.
What configurations are affected by CVE-2024-52287?
CVE-2024-52287 affects the OAuth client_credentials and device_code grants, allowing tokens to be issued with incorrectly configured scopes.
Who is affected by CVE-2024-52287?
Organizations using authentik versions 2024.8.5 through 2024.10.3 are affected by CVE-2024-52287.
What software does CVE-2024-52287 impact?
CVE-2024-52287 impacts the authentik identity provider software.