CVE-2024-11623 - CVE House
Back to Database
Status published Medium CVE-2024-11623

Stored XSS in authentik

Vulnerability Description

Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application icons.  This action could only be performed by an authenticated admin user. The issue was fixed in 2024.10.4 release.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-11623

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Daniel Basta (NASK-PIB)

Affected Vendor

goauthentik

View all reports →

Affected Software

authentik
Vulnerable Versions:
0

Timeline

Official Publish: February 4th, 2025
Last Modified: February 12th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)