Описание
Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application icons. This action could only be performed by an authenticated admin user. The issue was fixed in 2024.10.4 release.
Ссылки
- Third Party Advisory
- Vendor Advisory
- Issue TrackingPatch
Уязвимые конфигурации
Конфигурация 1Версия до 2024.10.4 (исключая)
cpe:2.3:a:goauthentik:authentik:*:*:*:*:*:*:*:*
EPSS
Процентиль: 39%
0.00174
Низкий
4.8 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 4.8
github
около 1 года назад
Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application icons. This action could only be performed by an authenticated admin user. The issue was fixed in 2024.10.4 release.
EPSS
Процентиль: 39%
0.00174
Низкий
4.8 Medium
CVSS3
Дефекты
CWE-79