goauthentik kayıtları
goauthentik üreticisine ait 33 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %24,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-287 Improper Authentication11
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-284 Improper Access Control2
- CWE-269 Improper Privilege Management2
- CWE-345 Insufficient Verification of Data Authenticity2
- CWE-285 Improper Authorization2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
33 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-48228İstismar yok | OAuth2: PKCE can be fully circumventedgoauthentik · authentik · CWE-287 | Kritik9,8 | — | %1,2 | 21 Kas 2023 |
39İzleyin | CVE-2022-46145İstismar yok | authentik vulnerable to unauthorized user creation and potential account takeovergoauthentik · authentik · CWE-287 | Kritik9,8 | — | %1,2 | 2 Ara 2022 |
39İzleyin | CVE-2023-46249İstismar yok | authentik potential installation takeover when default admin user is deletedgoauthentik · authentik · CWE-287 | Kritik9,8 | — | %0,7 | 31 Eki 2023 |
39İzleyin | CVE-2024-38371İstismar yok | Insufficient access control for OAuth2 Device Code flow in authentikgoauthentik · authentik · CWE-284 | Kritik9,8 | — | %0,6 | 28 Haz 2024 |
39İzleyin | CVE-2026-49448İstismar yok | authentik: SourceStage bypass via empty POSTgoauthentik · authentik · CWE-287 | Kritik9,8 | — | %0,6 | 2 Haz 2026 |
37İzleyin | CVE-2026-42849İstismar yok | authentik: Reflected XSS in SFE AutosubmitStage allows IDP account takeovergoauthentik · authentik · CWE-79 | Kritik9,3 | — | %0,5 | 2 Haz 2026 |
36İzleyin | CVE-2024-47070İstismar yok | authentik vulnerable to password authentication bypass via X-Forwarded-For HTTP headergoauthentik · authentik · CWE-287 | Kritik9,0 | — | %0,6 | 27 Eyl 2024 |
35İzleyin | CVE-2022-23555İstismar yok | authentik vulnerable to Improper Authentication via invitation URL token reusegoauthentik · authentik · CWE-287 | Yüksek8,8 | — | %0,9 | 27 Ara 2022 |
35İzleyin | CVE-2024-37905İstismar yok | Improper Access Control and Incorrect Authorization in github.com/goauthentik/authentikgoauthentik · authentik · CWE-284 | Yüksek8,8 | — | %0,8 | 28 Haz 2024 |
35İzleyin | CVE-2024-23647İstismar yok | PKCE downgrade attack in Authentikgoauthentik · authentik · CWE-287 | Yüksek8,8 | — | %0,5 | 30 Oca 2024 |
35İzleyin | CVE-2026-49443İstismar yok | authentik: `UserSourceConnection.user` and `GroupSourceConnection.group` are changeable through the APIgoauthentik · authentik · CWE-287 | Yüksek8,8 | — | %0,4 | 2 Haz 2026 |
35İzleyin | CVE-2026-25922İstismar yok | authentik has a Signature Verification Bypass via SAML Assertion Wrappinggoauthentik · authentik · CWE-287 | Yüksek8,8 | — | %0,3 | 12 Şub 2026 |
34İzleyin | CVE-2026-47201İstismar yok | authentik: XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated usergoauthentik · authentik · CWE-20 | Yüksek8,5 | — | %0,3 | 2 Haz 2026 |
32İzleyin | CVE-2025-29928İstismar yok | authentik's deletion of sessions did not revoke sessions when using database session storagegoauthentik · authentik · CWE-384 | Yüksek8,0 | — | %0,4 | 28 Mar 2025 |
31İzleyin | CVE-2024-52289İstismar yok | authentik has an insecure default configuration for OAuth2 Redirect URIsgoauthentik · authentik · CWE-185 | Yüksek7,9 | — | %1,1 | 21 Kas 2024 |
30İzleyin | CVE-2026-25748İstismar yok | authentik has a forward authentication bypass with broken cookiegoauthentik · authentik · CWE-287 | Yüksek7,5 | — | %0,8 | 12 Şub 2026 |
30İzleyin | CVE-2024-42490İstismar yok | authentik has Insufficient Authorization for several API endpointsgoauthentik · authentik · CWE-285 | Yüksek7,5 | — | %0,5 | 22 Ağu 2024 |
29İzleyin | CVE-2023-36456İstismar yok | Authentik lacks Proxy IP headers validationgoauthentik · authentik · CWE-436 | Yüksek7,3 | — | %0,8 | 6 Tem 2023 |
28İzleyin | CVE-2026-25227İstismar yok | authentik affected by Remote Code Execution via Context Key Injection in PropertyMapping Test Endpointgoauthentik · authentik · CWE-94 | Yüksek7,2 | — | %0,8 | 12 Şub 2026 |
28İzleyin | CVE-2025-53942İstismar yok | authentik has an insufficient check for account active status during OAuth/SAML authenticationgoauthentik · authentik · CWE-269 | Yüksek7,1 | — | %0,5 | 23 Tem 2025 |
27İzleyin | CVE-2026-41569İstismar yok | authentik: WS-Federation wreply origin bypass can exfiltrate signed login responses to attacker-controlled endpointsgoauthentik · authentik · CWE-601 | Orta6,9 | — | %0,3 | 2 Haz 2026 |
27İzleyin | CVE-2026-41577İstismar yok | authentik: SAML source does not validate Conditions, timing, or audience on assertionsgoauthentik · authentik · CWE-345 | Orta6,9 | — | %0,2 | 2 Haz 2026 |
26İzleyin | CVE-2024-47077İstismar yok | authentik cross-provider token validation problemsgoauthentik · authentik · CWE-863 | Orta6,5 | — | %0,4 | 27 Eyl 2024 |
26İzleyin | CVE-2023-26481İstismar yok | Insufficient user check in FlowTokens by Email stagegoauthentik · authentik · CWE-345 | Orta6,5 | — | %0,3 | 3 Mar 2023 |
25İzleyin | CVE-2024-52287İstismar yok | authentik performs insufficient validation of OAuth scopesgoauthentik · authentik · CWE-285 | Orta6,4 | — | %0,6 | 21 Kas 2024 |
- CVE-2023-4822839İzleyin
OAuth2: PKCE can be fully circumvented
KritikCVSS 9,8İstismar yokEPSS %1goauthentik · authentik21 Kas 2023
- CVE-2022-4614539İzleyin
authentik vulnerable to unauthorized user creation and potential account takeover
KritikCVSS 9,8İstismar yokEPSS %1goauthentik · authentik2 Ara 2022
- CVE-2023-4624939İzleyin
authentik potential installation takeover when default admin user is deleted
KritikCVSS 9,8İstismar yokEPSS %1goauthentik · authentik31 Eki 2023
- CVE-2024-3837139İzleyin
Insufficient access control for OAuth2 Device Code flow in authentik
KritikCVSS 9,8İstismar yokEPSS %1goauthentik · authentik28 Haz 2024
- CVE-2026-4944839İzleyin
authentik: SourceStage bypass via empty POST
KritikCVSS 9,8İstismar yokEPSS %1goauthentik · authentik2 Haz 2026
- CVE-2026-4284937İzleyin
authentik: Reflected XSS in SFE AutosubmitStage allows IDP account takeover
KritikCVSS 9,3İstismar yokEPSS %0goauthentik · authentik2 Haz 2026
- CVE-2024-4707036İzleyin
authentik vulnerable to password authentication bypass via X-Forwarded-For HTTP header
KritikCVSS 9,0İstismar yokEPSS %1goauthentik · authentik27 Eyl 2024
- CVE-2022-2355535İzleyin
authentik vulnerable to Improper Authentication via invitation URL token reuse
YüksekCVSS 8,8İstismar yokEPSS %1goauthentik · authentik27 Ara 2022
- CVE-2024-3790535İzleyin
Improper Access Control and Incorrect Authorization in github.com/goauthentik/authentik
YüksekCVSS 8,8İstismar yokEPSS %1goauthentik · authentik28 Haz 2024
- CVE-2024-2364735İzleyin
PKCE downgrade attack in Authentik
YüksekCVSS 8,8İstismar yokEPSS %1goauthentik · authentik30 Oca 2024
- CVE-2026-4944335İzleyin
authentik: `UserSourceConnection.user` and `GroupSourceConnection.group` are changeable through the API
YüksekCVSS 8,8İstismar yokEPSS %0goauthentik · authentik2 Haz 2026
- CVE-2026-2592235İzleyin
authentik has a Signature Verification Bypass via SAML Assertion Wrapping
YüksekCVSS 8,8İstismar yokEPSS %0goauthentik · authentik12 Şub 2026
- CVE-2026-4720134İzleyin
authentik: XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated user
YüksekCVSS 8,5İstismar yokEPSS %0goauthentik · authentik2 Haz 2026
- CVE-2025-2992832İzleyin
authentik's deletion of sessions did not revoke sessions when using database session storage
YüksekCVSS 8,0İstismar yokEPSS %0goauthentik · authentik28 Mar 2025
- CVE-2024-5228931İzleyin
authentik has an insecure default configuration for OAuth2 Redirect URIs
YüksekCVSS 7,9İstismar yokEPSS %1goauthentik · authentik21 Kas 2024
- CVE-2026-2574830İzleyin
authentik has a forward authentication bypass with broken cookie
YüksekCVSS 7,5İstismar yokEPSS %1goauthentik · authentik12 Şub 2026
- CVE-2024-4249030İzleyin
authentik has Insufficient Authorization for several API endpoints
YüksekCVSS 7,5İstismar yokEPSS %0goauthentik · authentik22 Ağu 2024
- CVE-2023-3645629İzleyin
Authentik lacks Proxy IP headers validation
YüksekCVSS 7,3İstismar yokEPSS %1goauthentik · authentik6 Tem 2023
- CVE-2026-2522728İzleyin
authentik affected by Remote Code Execution via Context Key Injection in PropertyMapping Test Endpoint
YüksekCVSS 7,2İstismar yokEPSS %1goauthentik · authentik12 Şub 2026
- CVE-2025-5394228İzleyin
authentik has an insufficient check for account active status during OAuth/SAML authentication
YüksekCVSS 7,1İstismar yokEPSS %1goauthentik · authentik23 Tem 2025
- CVE-2026-4156927İzleyin
authentik: WS-Federation wreply origin bypass can exfiltrate signed login responses to attacker-controlled endpoints
OrtaCVSS 6,9İstismar yokEPSS %0goauthentik · authentik2 Haz 2026
- CVE-2026-4157727İzleyin
authentik: SAML source does not validate Conditions, timing, or audience on assertions
OrtaCVSS 6,9İstismar yokEPSS %0goauthentik · authentik2 Haz 2026
- CVE-2024-4707726İzleyin
authentik cross-provider token validation problems
OrtaCVSS 6,5İstismar yokEPSS %0goauthentik · authentik27 Eyl 2024
- CVE-2023-2648126İzleyin
Insufficient user check in FlowTokens by Email stage
OrtaCVSS 6,5İstismar yokEPSS %0goauthentik · authentik3 Mar 2023
- CVE-2024-5228725İzleyin
authentik performs insufficient validation of OAuth scopes
OrtaCVSS 6,4İstismar yokEPSS %1goauthentik · authentik21 Kas 2024