Skip to content

Unauthorized user creation and potential account takeover

High
BeryJu published GHSA-mjfw-54m5-fvjf Dec 2, 2022

Package

authentik

Affected versions

< 2022.11.2
< 2022.10.2

Patched versions

2022.11.2
2022.10.2

Description

Impact

With the default flows, unauthenticated users can create new accounts in authentik. If a flow exists that allows for email-verified password recovery, this can be used to overwrite the email address of admin accounts and take over their accounts

Patches

authentik 2022.11.2 and 2022.10.2 fix this issue, for other versions the workaround can be used.

Workarounds

A policy can be created and bound to the default-user-settings-flow flow with the following contents

return request.user.is_authenticated

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

CVE-2022-46145

Weaknesses

No CWEs

Credits