Skip to main content

CVE-2024-38371

8.6
HIGHCVSS v3.1 Base Score
0.27%
LOW RiskEPSS (51st percentile)

authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when using the OAuth2 Device code flow. This could potentially allow users without the correct authorization to get OAuth tokens for an application and access it. This issue has been patched in version(s) 2024.6.0, 2024.2.4 and 2024.4.3.

Published: 6/28/2024
Modified: 8/21/2025
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.6HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

EPSS Score (Exploitation Probability)

0.27%LOW Exploitation Risk
51st percentile

This vulnerability has a 0.27% probability of being exploited in the next 30 days, ranking higher than 51% of all scored CVEs.

Related Vulnerabilities