Interpretation Conflict Affecting goauthentik.io package, versions <2023.4.3>=2023.5.0 <2023.5.5


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.1% (44th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GOAUTHENTIKIO-5759296
  • published7 Jul 2023
  • disclosed7 Jul 2023
  • creditthijsa

Introduced: 7 Jul 2023

CVE-2023-36456  (opens in a new tab)
CWE-436  (opens in a new tab)

How to fix?

Upgrade goauthentik.io to version 2023.4.3, 2023.5.5 or higher.

Overview

Affected versions of this package are vulnerable to Interpretation Conflict due to not verifying the source of the X-Forwarded-For and X-Real-IP headers both in the Python code and the go code.

Note:

Only authentik setups that are directly accessible by users without a reverse proxy are susceptible to this.

CVSS Scores

version 3.1