Executive brief
Authentik vulnerable to PKCE downgrade attack in goauthentik.io
Affected products
- Go goauthentik.io
Junglewise Threat Intelligence
CVE-2024-23647 · Severity: low · CVSS 3.1 · Published 2024-06-28
Technologies: goauthentik.io (Go). Vendors: Go.
Authentik vulnerable to PKCE downgrade attack in goauthentik.io