CVE-2023-6545

The package authelia-bhf included in Beckhoffs TwinCAT/BSD is prone to an open redirect that allows a remote unprivileged attacker to redirect a user to another site. This may have limited impact to integrity and does solely affect anthelia-bhf the Beckhoff fork of authelia.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:beckhoff:authelia-bhf:*:*:*:*:*:*:*:*
cpe:2.3:o:beckhoff:twincat\/bsd:-:*:*:*:*:*:*:*

History

19 Dec 2023, 18:35

Type Values Removed Values Added
Summary
  • (es) El paquete authelia-bhf incluido en Beckhoffs TwinCAT/BSD es propenso a una redirección abierta que permite a un atacante remoto sin privilegios redirigir a un usuario a otro sitio. Esto puede tener un impacto limitado en la integridad y afecta únicamente a anthelia-bhf, la bifurcación Beckhoff de authelia.
CVSS v2 : unknown
v3 : 4.3
v2 : unknown
v3 : 4.7
CPE cpe:2.3:o:beckhoff:twincat\/bsd:-:*:*:*:*:*:*:*
cpe:2.3:a:beckhoff:authelia-bhf:*:*:*:*:*:*:*:*
References () https://cert.vde.com/en/advisories/VDE-2023-067/ - () https://cert.vde.com/en/advisories/VDE-2023-067/ - Third Party Advisory
References () https://download.beckhoff.com/download/Document/product-security/Advisories/advisory-2023-001.pdf - () https://download.beckhoff.com/download/Document/product-security/Advisories/advisory-2023-001.pdf - Vendor Advisory
First Time Beckhoff
Beckhoff authelia-bhf
Beckhoff twincat\/bsd

14 Dec 2023, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-14 14:15

Updated : 2024-02-15 11:15


NVD link : CVE-2023-6545

Mitre link : CVE-2023-6545

CVE.ORG link : CVE-2023-6545


JSON object : View

Products Affected

beckhoff

  • authelia-bhf
  • twincat\/bsd
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')