VendorsOpenIDCmod_auth_openidcany version
Vulnerabilities

OpenIDC mod_auth_openidc any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2017-6413
The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.6 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an "AuthType oauth20" configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic.
Published 2017-03-02 · Modified
8.6EPSS 0.043
CVE-2017-6062
The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.5 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an "OIDCUnAuthAction pass" configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic.
Published 2017-03-02 · Modified
8.6EPSS 0.036
CVE-2017-6059
Mod_auth_openidc.c in the Ping Identity OpenID Connect authentication module for Apache (aka mod_auth_openidc) before 2.14 allows remote attackers to spoof page content via a malicious URL provided to the user, which triggers an invalid request.
Published 2017-04-12 · Modified
7.5EPSS 0.052
CVE-2021-20718
mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vectors.
Published 2021-05-20 · Modified
7.5EPSS 0.034
CVE-2021-32785
Format string bug in the Redis cache implementation
Published 2021-07-22 · Modified
7.5EPSS 0.027
CVE-2023-28625
mod_auth_openidc core dump when OIDCStripCookies is set and an empty Cookie header is supplied
Published 2023-04-03 · Analyzed
7.5EPSS 0.013
CVE-2024-24814
Denial of service when manipulating mod_auth_openidc_session_chunks cookie in mod_auth_openidc
Published 2024-02-13 · Modified
7.5EPSS 0.013
CVE-2021-32786
Open Redirect in oidc_validate_redirect_url()
Published 2021-07-22 · Modified
6.1EPSS 0.024
CVE-2019-20479
A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning.
Published 2020-02-20 · Modified
6.1EPSS 0.019
CVE-2021-39191
URL Redirection to Untrusted Site ('Open Redirect') in mod_auth_openidc
Published 2021-09-03 · Modified
6.1EPSS 0.017
CVE-2019-14857
A flaw was found in mod_auth_openidc before version 2.4.0.1. An open redirect issue exists in URLs with trailing slashes similar to CVE-2019-3877 in mod_auth_mellon.
Published 2019-11-26 · Modified
6.1EPSS 0.016
CVE-2021-32792
XSS vulnerability when using OIDCPreservePost On in mod_auth_openidc
Published 2021-07-26 · Modified
6.1EPSS 0.015
CVE-2019-1010247
ZmartZone IAM mod_auth_openidc 2.3.10.1 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Redirecting the user to a phishing page or interacting with the application on behalf of the user. The component is: File: src/mod_auth_openidc.c, Line: 3109. The fixed version is: 2.3.10.2.
Published 2019-07-19 · Modified
6.1EPSS 0.013
CVE-2022-23527
Open Redirect in oidc_validate_redirect_url()
Published 2022-12-14 · Modified
6.1EPSS 0.009
CVE-2021-32791
Hardcoded static IV and AAD with a reused key in AES GCM encryption in mod_auth_openidc
Published 2021-07-26 · Modified
5.9EPSS 0.015