Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application icons.
This action could only be performed by an authenticated admin user.
The issue was fixed in 2024.10.4 release.
Metrics
Affected Vendors & Products
References
History
Thu, 21 Aug 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:goauthentik:authentik:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 12 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 04 Feb 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application icons. This action could only be performed by an authenticated admin user. The issue was fixed in 2024.10.4 release. | |
| Title | Stored XSS in authentik | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published: 2025-02-04T13:34:11.029Z
Updated: 2025-02-12T17:10:12.746Z
Reserved: 2024-11-22T15:12:36.191Z
Link: CVE-2024-11623
Updated: 2025-02-12T17:09:55.312Z
Status : Analyzed
Published: 2025-02-04T14:15:30.480
Modified: 2025-08-21T18:41:13.607
Link: CVE-2024-11623
No data.