Логотип exploitDog
bind:CVE-2024-23647
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-23647

Количество 2

Количество 2

nvd логотип

CVE-2024-23647

около 2 лет назад

Authentik is an open-source Identity Provider. There is a bug in our implementation of PKCE that allows an attacker to circumvent the protection that PKCE offers. PKCE adds the code_challenge parameter to the authorization request and adds the code_verifier parameter to the token request. Prior to 2023.8.7 and 2023.10.7, a downgrade scenario is possible: if the attacker removes the code_challenge parameter from the authorization request, authentik will not do the PKCE check. Because of this bug, an attacker can circumvent the protection PKCE offers, such as CSRF attacks and code injection attacks. Versions 2023.8.7 and 2023.10.7 fix the issue.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-mrx3-gxjx-hjqj

около 2 лет назад

Authentik vulnerable to PKCE downgrade attack

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-23647

Authentik is an open-source Identity Provider. There is a bug in our implementation of PKCE that allows an attacker to circumvent the protection that PKCE offers. PKCE adds the code_challenge parameter to the authorization request and adds the code_verifier parameter to the token request. Prior to 2023.8.7 and 2023.10.7, a downgrade scenario is possible: if the attacker removes the code_challenge parameter from the authorization request, authentik will not do the PKCE check. Because of this bug, an attacker can circumvent the protection PKCE offers, such as CSRF attacks and code injection attacks. Versions 2023.8.7 and 2023.10.7 fix the issue.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-mrx3-gxjx-hjqj

Authentik vulnerable to PKCE downgrade attack

CVSS3: 6.5
0%
Низкий
около 2 лет назад

Уязвимостей на страницу