CVE-2024-47077

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Sep 27, 2024
Updated: Sep 30, 2024
CWE ID 863

Summary

CVE-2024-47077 is a vulnerability affecting the open-source identity provider, authentik, prior to versions 2024.8.3 and 2024.6.5. This issue allows applications to steal access tokens, enabling them to impersonate users against any other proxy provider. Additionally, users can misuse legitimately issued access tokens to access applications they are not authorized to use. The impact of this vulnerability is significant for organizations using multiple proxy provider applications with different trust domains or access control. Fortunately, versions 2024.8.3 and 2024.6.5 have been released to address this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share