PT-2021-4490 · Authelia+1 · Authelia+1
Ricardo Pesqueira
+1
·
Published
2021-05-28
·
Updated
2021-12-20
·
CVE-2021-32637
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Authelia versions prior to 4.29.3
Description
The issue affects users who are using nginx ngx http auth request module with Authelia. It allows a malicious individual who crafts a malformed HTTP request to bypass the authentication mechanism. This could theoretically affect other proxy servers, but all of the ones officially supported except nginx do not allow malformed URI paths.
Recommendations
For versions prior to 4.29.3, the most relevant workaround is upgrading to version 4.29.3 or later.
Alternatively, a git patch can be applied to version 4.25.1 or other versions upon request.
As a temporary workaround, consider adding a block that fails requests containing a malformed URI in the internal location block.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Authelia
Nginx