PT-2021-4490 · Authelia+1 · Authelia+1

Ricardo Pesqueira

+1

·

Published

2021-05-28

·

Updated

2021-12-20

·

CVE-2021-32637

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Authelia versions prior to 4.29.3
Description The issue affects users who are using nginx ngx http auth request module with Authelia. It allows a malicious individual who crafts a malformed HTTP request to bypass the authentication mechanism. This could theoretically affect other proxy servers, but all of the ones officially supported except nginx do not allow malformed URI paths.
Recommendations For versions prior to 4.29.3, the most relevant workaround is upgrading to version 4.29.3 or later. Alternatively, a git patch can be applied to version 4.25.1 or other versions upon request. As a temporary workaround, consider adding a block that fails requests containing a malformed URI in the internal location block.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05124
CVE-2021-32637
GHSA-68WM-PFJF-WQP6

Affected Products

Authelia
Nginx