authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get a token from authentik with scopes that haven't been configured in authentik. authentik 2024.8.5 and 2024.10.3 fix this issue.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-45990 authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get a token from authentik with scopes that haven't been configured in authentik. authentik 2024.8.5 and 2024.10.3 fix this issue.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 21 Aug 2025 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Thu, 21 Nov 2024 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Goauthentik
Goauthentik authentik
CPEs cpe:2.3:a:goauthentik:authentik:*:*:*:*:*:*:*:*
Vendors & Products Goauthentik
Goauthentik authentik
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 21 Nov 2024 17:30:00 +0000

Type Values Removed Values Added
Description authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get a token from authentik with scopes that haven't been configured in authentik. authentik 2024.8.5 and 2024.10.3 fix this issue.
Title authentik performs insufficient validation of OAuth scopes
Weaknesses CWE-285
References
Metrics cvssV4_0

{'score': 6.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-11-21T21:05:11.287Z

Reserved: 2024-11-06T19:00:26.393Z

Link: CVE-2024-52287

cve-icon Vulnrichment

Updated: 2024-11-21T21:04:57.706Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-21T18:15:11.570

Modified: 2025-08-21T19:21:32.553

Link: CVE-2024-52287

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.