goauthentik
CVE Severity Distribution (All Time)
Timeline Overview
Products
View allRecent CVEs
View allauthentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get …
authentik is an open-source identity provider. Redirect URIs in the OAuth2 provider in authentik are checked by RegEx comparison. When no Redirect UR…
authentik is an open-source identity provider. Due to the usage of a non-constant time comparison for the /-/metrics/ endpoint it was possible to bru…
authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one application can be stolen by that…
authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024.8.3 and 2024.6.5 allows bypassing password login…
authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. The main …