CVE ID | CVE-2024-11623 |
Publication date | 04 February 2025 |
Vendor | goauthentik |
Product | authentik |
Vulnerable versions | All before 2024.10.4 |
Vulnerability type (CWE) | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') (CWE-79) |
Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in authentik software and participated in coordination of its disclosure.
The vulnerability CVE-2024-11623: Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application icons. This action could only be performed by an authenticated attacker with administrative privileges. A user who followed a link to this icon would execute the script embedded in the SVG file in their browser.
The issue was fixed in 2024.10.4 release.
Credits
We thank Daniel Basta (NASK-PIB) for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.