Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application icons.  This action could only be performed by an authenticated admin user. The issue was fixed in 2024.10.4 release.
History

Wed, 12 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Feb 2025 13:45:00 +0000

Type Values Removed Values Added
Description Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application icons.  This action could only be performed by an authenticated admin user. The issue was fixed in 2024.10.4 release.
Title Stored XSS in authentik
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2025-02-12T17:10:12.746Z

Reserved: 2024-11-22T15:12:36.191Z

Link: CVE-2024-11623

cve-icon Vulnrichment

Updated: 2025-02-12T17:09:55.312Z

cve-icon NVD

Status : Received

Published: 2025-02-04T14:15:30.480

Modified: 2025-02-04T14:15:30.480

Link: CVE-2024-11623

cve-icon Redhat

No data.