CVE-2024-52287
Severity CVSS v4.0:
MEDIUM
Type:
CWE-285
Improper Authorization
Publication date:
21/11/2024
Last modified:
21/08/2025
Description
authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get a token from authentik with scopes that haven't been configured in authentik. authentik 2024.8.5 and 2024.10.3 fix this issue.
Impact
Base Score 4.0
6.40
Severity 4.0
MEDIUM
Base Score 3.x
7.20
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:goauthentik:authentik:*:*:*:*:*:*:*:* | 2024.8.5 (excluding) | |
| cpe:2.3:a:goauthentik:authentik:*:*:*:*:*:*:*:* | 2024.10.0 (including) | 2024.10.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



