#VU127134 Information Exposure Through Timing Discrepancy in authentik - CVE-2024-52307
Published: November 21, 2024 / Updated: April 23, 2026
authentik
Authentik Security Inc
Description
The vulnerability allows a remote attacker to disclose sensitive information and modify data.
The vulnerability exists due to observable timing discrepancy in the /-/metrics/ endpoint when comparing authentication data. A remote attacker can send repeated requests to brute-force the SECRET_KEY to disclose sensitive information and modify data.
The issue can enable signing new cookies or modifying existing cookies after recovering the SECRET_KEY.