关键信息总结 漏洞标题 Unauthorized user creation and potential account takeover 漏洞ID CVE-2022-46145 GHSA-mfqw-54m5-fvjf 严重程度 High 影响版本 < 2022.11.2 < 2022.10.2 修复版本 2022.11.2 2022.10.2 影响描述 With the default flows, unauthenticated users can create new accounts in authentik. If a flow exists that allows for email-verified password recovery, this can be used to overwrite the email address of admin accounts and take over their accounts. 修复措施 authentik 2022.11.2 and 2022.10.2 fix this issue, for other versions the workaround can be used. 临时变通方案 A policy can be created and bound to the flow with the following contents 联系方式 Email: security@goauthentik.io