Description
goauthentik is an open-source Identity Provider. In affected versions using a recovery flow with an identification stage an attacker is able to determine if a username exists. Only setups configured with a recovery flow are impacted by this. Anyone with a user account on a system with the recovery flow described above is susceptible to having their username/email revealed as existing. An attacker can easily enumerate and check users' existence using the recovery flow, as a clear message is shown when a user doesn't exist. Depending on configuration this can either be done by username, email, or both. This issue has been addressed in versions 2023.5.6 and 2023.6.2. Users are advised to upgrade. There are no known workarounds for this issue.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://github.com/goauthentik/authentik/security/advisories/GHSA-vmf9-6pcv-xr87
Scores
CVSS v3
5.3
EPSS
0.0069
EPSS Percentile
71.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-203
Status
published
Products (2)
goauthentik/api
2023.6.0 - 2023.6.2npm
goauthentik/authentik
< 2023.5.6
Published
Aug 29, 2023
Tracked Since
Feb 18, 2026