CVE-2021-29456

See a problem?
Source
https://nvd.nist.gov/vuln/detail/CVE-2021-29456
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-29456.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-29456
Aliases
Withdrawn
2024-05-15T05:32:38.131987Z
Published
2021-04-21T19:15:35Z
Modified
2023-11-29T08:45:50.832883Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Authelia is an open-source authentication and authorization server providing 2-factor authentication and single sign-on (SSO) for your applications via a web portal. In versions 4.27.4 and earlier, utilizing a HTTP query parameter an attacker is able to redirect users from the web application to any domain, including potentially malicious sites. This security issue does not directly impact the security of the web application itself. As a workaround, one can use a reverse proxy to strip the query parameter from the affected endpoint. There is a patch for version 4.28.0.

References

Affected packages

Git / github.com/authelia/authelia

Affected ranges

Type
GIT
Repo
https://github.com/authelia/authelia
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v1.*

v1.0.1
v1.0.10
v1.0.11
v1.0.7
v1.0.8
v1.0.9

v2.*

v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.1.7
v2.1.8
v2.1.9

v3.*

v3.0.1
v3.1.0
v3.1.1
v3.1.2
v3.1.3
v3.1.4
v3.12.0
v3.13.0
v3.14.0
v3.15.0
v3.16.1
v3.16.2
v3.2.0
v3.3.0
v3.3.1
v3.3.19
v3.3.2
v3.4.0
v3.4.1
v3.4.2
v3.5.0
v3.6.0
v3.7.0
v3.7.1
v3.8.0
v3.8.2
v3.8.3

v4.*

v4.0.0
v4.0.0-alpha1
v4.0.0-alpha2
v4.1.0
v4.10.0
v4.11.0
v4.12.0
v4.13.0
v4.13.1
v4.14.0
v4.14.1
v4.14.2
v4.15.0
v4.15.1
v4.16.0
v4.17.0
v4.18.0
v4.18.1
v4.19.0
v4.19.1
v4.19.2
v4.2.0
v4.20.0
v4.21.0
v4.22.0
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.25.0
v4.25.1
v4.25.2
v4.26.0
v4.26.1
v4.26.2
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.3.0
v4.4.0
v4.5.0
v4.5.1
v4.6.0
v4.7.0
v4.7.1
v4.7.2
v4.8.0
v4.9.0
v4.9.1