BIT-authentik-2024-21637

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/authentik/BIT-authentik-2024-21637.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-authentik-2024-21637
Aliases
Published
2026-04-16T23:36:10.878Z
Modified
2026-04-17T04:57:18.076550005Z
Summary
XSS in Authentik via JavaScript-URI as Redirect URI and form_post Response Mode
Details

Authentik is an open-source Identity Provider. Authentik is a vulnerable to a reflected Cross-Site Scripting vulnerability via JavaScript-URIs in OpenID Connect flows with response_mode=form_post. This relatively user could use the described attacks to perform a privilege escalation. This vulnerability has been patched in versions 2023.10.6 and 2023.8.6.

Database specific
{
    "cpes": [
        "cpe:2.3:a:goauthentik:authentik:*:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / authentik

Package

Name
authentik
Purl
pkg:bitnami/authentik

Severity

  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
2023.8.0
Fixed
2023.8.6
Introduced
2023.10.0
Fixed
2023.10.6

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/authentik/BIT-authentik-2024-21637.json"