SB2024092798 - Multiple vulnerabilities in authentik



SB2024092798 - Multiple vulnerabilities in authentik

Published: September 27, 2024 Updated: April 23, 2026

Security Bulletin ID SB2024092798
CSH Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Improper Authentication (CVE-ID: CVE-2024-47070)

The vulnerability allows a remote attacker to bypass authentication and authorize as any account with a known login or email address.

The vulnerability exists due to improper authentication in authentication and authorization flows when processing an X-Forwarded-For header with an unparsable IP address. A remote attacker can send a specially crafted request with a malformed X-Forwarded-For header to bypass authentication and authorize as any account with a known login or email address.

Exploitation is possible when the X-Forwarded-For header is not correctly controlled and policies are bound to authentication or authorization flows.


2) Incorrect authorization (CVE-ID: CVE-2024-47077)

The vulnerability allows a remote user to gain unauthorized access to another application's resources.

The vulnerability exists due to incorrect authorization in the /application/o/introspect/ endpoint when validating bearer tokens during token introspection. A remote user can present an access token issued for one application to impersonate the user against another application and gain unauthorized access to another application's resources.


Remediation

Install update from vendor's website.