PT-2023-7820 · Beckhoff · Authelia-Bhf+1

Benedikt Kühne

·

Published

2023-12-11

·

Updated

2024-02-15

·

CVE-2023-6545

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Beckhoff TwinCAT/BSD (affected versions not specified)
Description The package authelia-bhf included in Beckhoff's TwinCAT/BSD is prone to an open redirect, allowing a remote unprivileged attacker to redirect a user to another site. This may have limited impact to integrity and does solely affect anthelia-bhf, the Beckhoff fork of authelia. The vulnerability can be exploited by sending a specially crafted HTTP request, enabling the attacker to redirect the user to arbitrary websites.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Open Redirect

Weakness Enumeration

Related Identifiers

BDU:2023-08887
CVE-2023-6545

Affected Products

Twincat/Bsd
Authelia-Bhf