CVE-2019-14857Open Redirect in MOD Auth Openidc

CWE-601Open Redirect8 documents7 sources
Severity
6.1MEDIUMNVD
EPSS
0.7%
top 28.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 26
Latest updateMay 24

Description

A flaw was found in mod_auth_openidc before version 2.4.0.1. An open redirect issue exists in URLs with trailing slashes similar to CVE-2019-3877 in mod_auth_mellon.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-797h-qjwj-28jc: mod_auth_openidc before version 22022-05-24
CVEList
CVE-2019-14857: A flaw was found in mod_auth_openidc before version 22019-11-26
OSV
CVE-2019-14857: A flaw was found in mod_auth_openidc before version 22019-11-26

📋Vendor Advisories

2
Red Hat
mod_auth_openidc: Open redirect in logout url when using URLs with leading slashes2019-10-02
Debian
CVE-2019-14857: libapache2-mod-auth-openidc - A flaw was found in mod_auth_openidc before version 2.4.0.1. An open redirect is...2019

💬Community

2
Bugzilla
CVE-2019-14857 mod_auth_openidc: Open redirect in logout url when using URLs with leading slashes2019-10-10
Bugzilla
CVE-2019-14857 mod_auth_openidc: Open redirect in logout url when using URLs with backslashes [fedora-all]2019-10-10
CVE-2019-14857 — Open Redirect in MOD Auth Openidc | cvebase