Skip to main content

CVE-2022-46145

8.1
HIGHCVSS v3.1 Base Score
1.97%
LOW RiskEPSS (84th percentile)

authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized user creation and potential account takeover. With the default flows, unauthenticated users can create new accounts in authentik. If a flow exists that allows for email-verified password recovery, this can be used to overwrite the email address of admin accounts and take over their accounts. authentik 2022.11.2 and 2022.10.2 fix this issue. As a workaround, a policy can be created and bound to the `default-user-settings-flow flow` with the contents `return request.user.is_authenticated`.

Published: 12/2/2022
Modified: 11/21/2024
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.1HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

1.97%LOW Exploitation Risk
84th percentile

This vulnerability has a 1.97% probability of being exploited in the next 30 days, ranking higher than 84% of all scored CVEs.

Related Vulnerabilities