Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application icons.
This action could only be performed by an authenticated admin user.
The issue was fixed in 2024.10.4 release.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Feb 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 04 Feb 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application icons. This action could only be performed by an authenticated admin user. The issue was fixed in 2024.10.4 release. | |
Title | Stored XSS in authentik | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2025-02-12T17:10:12.746Z
Reserved: 2024-11-22T15:12:36.191Z
Link: CVE-2024-11623

Updated: 2025-02-12T17:09:55.312Z

Status : Received
Published: 2025-02-04T14:15:30.480
Modified: 2025-02-04T14:15:30.480
Link: CVE-2024-11623

No data.