Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-45990 | authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get a token from authentik with scopes that haven't been configured in authentik. authentik 2024.8.5 and 2024.10.3 fix this issue. |
Thu, 21 Aug 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 21 Nov 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Goauthentik
Goauthentik authentik |
|
| CPEs | cpe:2.3:a:goauthentik:authentik:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Goauthentik
Goauthentik authentik |
|
| Metrics |
ssvc
|
Thu, 21 Nov 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get a token from authentik with scopes that haven't been configured in authentik. authentik 2024.8.5 and 2024.10.3 fix this issue. | |
| Title | authentik performs insufficient validation of OAuth scopes | |
| Weaknesses | CWE-285 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-11-21T21:05:11.287Z
Reserved: 2024-11-06T19:00:26.393Z
Link: CVE-2024-52287
Updated: 2024-11-21T21:04:57.706Z
Status : Analyzed
Published: 2024-11-21T18:15:11.570
Modified: 2025-08-21T19:21:32.553
Link: CVE-2024-52287
No data.
OpenCVE Enrichment
No data.
EUVD