CVE-2021-32637
Last modified
CVE-2021-32637 is a critical-severity vulnerability rated 10/10 on the CVSS scale. Authelia is a a single sign-on multi-factor portal for web apps. This affects uses who are using nginx ngx_http_auth_request_module with Authelia, it allows a malicious individual who crafts a malformed HTTP request to bypass the authentication mechanism. EPSS estimates a 1.87% chance of exploitation in the next 30 days.
Description
Authelia is a a single sign-on multi-factor portal for web apps. This affects uses who are using nginx ngx_http_auth_request_module with Authelia, it allows a malicious individual who crafts a malformed HTTP request to bypass the authentication mechanism. It additionally could theoretically affect other proxy servers, but all of the ones we officially support except nginx do not allow malformed URI paths. The problem is rectified entirely in v4.29.3. As this patch is relatively straightforward we can back port this to any version upon request. Alternatively we are supplying a git patch to 4.25.1 which should be relatively straightforward to apply to any version, the git patches for specific versions can be found in the references. The most relevant workaround is upgrading. You can also add a block which fails requests that contains a malformed URI in the internal location block.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Authelia | Authelia | >= 4.0.0, < 4.25.1 |
| Authelia | Authelia | >= 4.26.0, < 4.29.3 |
References
- https://github.com/authelia/authelia/commit/c62dbd43d6e69ae81530e7c4f8763857f8ff1ddaPatch, Third Party Advisory
- https://github.com/authelia/authelia/security/advisories/GHSA-68wm-pfjf-wqp6Exploit, Mitigation, Patch, Third Party Advisory
- https://github.com/authelia/authelia/commit/c62dbd43d6e69ae81530e7c4f8763857f8ff1ddaPatch, Third Party Advisory
- https://github.com/authelia/authelia/security/advisories/GHSA-68wm-pfjf-wqp6Exploit, Mitigation, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-32637?
How severe is CVE-2021-32637?
How do I fix CVE-2021-32637?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-32630Admidio is a free, open source user management system for we…8.8
- CVE-2021-32631Common is a package of common modules that can be accessed b…6.5
- CVE-2021-32632Pajbot is a Twitch chat bot. Pajbot versions prior to 1.52 a…4.3
- CVE-2021-32633Zope is an open-source web application server. In Zope versi…8.8
- CVE-2021-32634Emissary is a distributed, peer-to-peer, data-driven workflo…7.2
- CVE-2021-32635Singularity is an open source container platform. In verions…6.3
- CVE-2021-32638Github's CodeQL action is provided to run CodeQL-based code …4.4
- CVE-2021-32639Emissary is a P2P-based, data-driven workflow engine. Emissa…9.9
- CVE-2021-3264SQL Injection vulnerability in cxuucms 3.1 ivia the pid para…7.2
- CVE-2021-32640ws is an open source WebSocket client and server library for…5.3
- CVE-2021-32641auth0-lock is Auth0's signin solution. Versions of nauth0-lo…6.1
- CVE-2021-32642radsecproxy is a generic RADIUS proxy that supports both UDP…9.4
Are you affected by CVE-2021-32637?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
