PT-2024-18987 · Authentik · Authentik

Lauritzh

·

Published

2024-01-10

·

Updated

2026-04-16

·

CVE-2024-21637

CVSS v3.1

7.6

High

VectorAV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Authentik versions prior to 2023.10.6 Authentik versions prior to 2023.8.6
Description Authentik is an open-source Identity Provider that is vulnerable to a reflected Cross-Site Scripting vulnerability via JavaScript-URIs in OpenID Connect flows with response mode=form post. This vulnerability could be used to perform a privilege escalation.
Recommendations For versions prior to 2023.10.6, update to version 2023.10.6 or later to resolve the issue. For versions prior to 2023.8.6, update to version 2023.8.6 or later to resolve the issue. As a temporary workaround, consider restricting the use of response mode=form post in OpenID Connect flows until a patch is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-AUTHENTIK-2024-21637
CVE-2024-21637
GHSA-RJPR-7W8C-GV3J

Affected Products

Authentik