CVE-2021-29456 Information
Jun 07, 2022
cve
Description
Authelia is an open-source authentication and authorization server providing 2-factor authentication and single sign-on (SSO) for your applications via a web portal. In versions 4.27.4 and earlier utilizing a HTTP query parameter an attacker is able to redirect users from the web application to any domain including potentially malicious sites. This security issue does not directly impact the security of the web application itself. As a workaround one can use a reverse proxy to strip the query parameter from the affected endpoint. There is a patch for version 4.28.0.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Reference
https://github.com/authelia/authelia/security/advisories/GHSA-36f2-fcrx-fp4j
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
5.4
Share on: