CVE-2019-20479Open Redirect in MOD Auth Openidc

CWE-601Open Redirect8 documents7 sources
Severity
6.1MEDIUMNVD
EPSS
0.5%
top 35.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 20
Latest updateMay 24

Description

A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

Also affects: Debian Linux 8.0, 9.0, Fedora 31, 32

Patches

🔴Vulnerability Details

3
GHSA
GHSA-5fmg-x3vm-cm8v: A flaw was found in mod_auth_openidc before version 22022-05-24
OSV
CVE-2019-20479: A flaw was found in mod_auth_openidc before version 22020-02-20
CVEList
CVE-2019-20479: A flaw was found in mod_auth_openidc before version 22020-02-20

📋Vendor Advisories

2
Red Hat
mod_auth_openidc: Open redirect issue exists in URLs with slash and backslash2019-11-12
Debian
CVE-2019-20479: libapache2-mod-auth-openidc - A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issu...2019

💬Community

2
Bugzilla
CVE-2019-20479 mod_auth_openidc: open redirect issue exists in URLs with slash and backslash [fedora-all]2020-02-20
Bugzilla
CVE-2019-20479 mod_auth_openidc: Open redirect issue exists in URLs with slash and backslash2020-02-20
CVE-2019-20479 — Open Redirect in MOD Auth Openidc | cvebase