Debian Libapache2-Mod-Auth-Openidc vulnerabilities
17 known vulnerabilities affecting debian/libapache2-mod-auth-openidc.
Total CVEs
17
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH8MEDIUM8LOW1
Vulnerabilities
Page 1 of 1
CVE-2017-6413P3HIGHCVSS 8.6fixed in libapache2-mod-auth-openidc 2.1.6-1 (bookworm)2017
CVE-2017-6413 [HIGH] CVE-2017-6413: libapache2-mod-auth-openidc - The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_o...
The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.6 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an "AuthType oauth20" configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic.
Scope: local
bookworm: resolved (fixed i
debian
CVE-2017-6062P3HIGHCVSS 8.6fixed in libapache2-mod-auth-openidc 2.1.5-1 (bookworm)2017
CVE-2017-6062 [HIGH] CVE-2017-6062: libapache2-mod-auth-openidc - The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_o...
The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.5 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an "OIDCUnAuthAction pass" configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic.
Scope: local
bookworm: resolved (fi
debian
CVE-2025-31492P3HIGHCVSS 8.2fixed in libapache2-mod-auth-openidc 2.4.12.3-2+deb12u3 (bookworm)2025
CVE-2025-31492 [HIGH] CVE-2025-31492: libapache2-mod-auth-openidc - mod_auth_openidc is an OpenID Certified authentication and authorization module ...
mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.16.11, a bug in a mod_auth_openidc results in disclosure of protected content to unauthenticated users. The conditions for disclosure are an OIDCProviderAuthReq
debian
CVE-2025-3891P3HIGHCVSS 7.5fixed in libapache2-mod-auth-openidc 2.4.12.3-2+deb12u4 (bookworm)2025
CVE-2025-3891 [HIGH] CVE-2025-3891: libapache2-mod-auth-openidc - A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allo...
A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.
Scope: local
bookworm: resolved (fixed in 2.4.12.3-2+deb12u4)
b
debian
CVE-2017-6059P3HIGHCVSS 7.5fixed in libapache2-mod-auth-openidc 2.1.5-1 (bookworm)2017
CVE-2017-6059 [HIGH] CVE-2017-6059: libapache2-mod-auth-openidc - Mod_auth_openidc.c in the Ping Identity OpenID Connect authentication module for...
Mod_auth_openidc.c in the Ping Identity OpenID Connect authentication module for Apache (aka mod_auth_openidc) before 2.14 allows remote attackers to spoof page content via a malicious URL provided to the user, which triggers an invalid request.
Scope: local
bookworm: resolved (fixed in 2.1.5-1)
bullseye: resolved (fixed in 2.1.5-1)
forky: resolved
debian
CVE-2021-32785P3MEDIUMCVSS 5.3fixed in libapache2-mod-auth-openidc 2.4.9-1 (bookworm)2021
CVE-2021-32785 [MEDIUM] CVE-2021-32785: libapache2-mod-auth-openidc - mod_auth_openidc is an authentication/authorization module for the Apache 2.x HT...
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. When mod_auth_openidc versions prior to 2.4.9 are configured to use an unencrypted Redis cache (`OIDCCacheEncrypt off`, `OIDCSessionType server-cach
debian
CVE-2024-24814P3HIGHCVSS 7.5fixed in libapache2-mod-auth-openidc 2.4.12.3-2+deb12u1 (bookworm)2024
CVE-2024-24814 [HIGH] CVE-2024-24814: libapache2-mod-auth-openidc - mod_auth_openidc is an OpenID Certified™ authentication and authorization module...
mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In affected versions missing input validation on mod_auth_openidc_session_chunks cookie value makes the server vulnerable to a denial of service (DoS) attack. An internal s
debian
CVE-2023-28625P3HIGHCVSS 7.5fixed in libapache2-mod-auth-openidc 2.4.12.3-2 (bookworm)2023
CVE-2023-28625 [HIGH] CVE-2023-28625: libapache2-mod-auth-openidc - mod_auth_openidc is an authentication and authorization module for the Apache 2....
mod_auth_openidc is an authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In versions 2.0.0 through 2.4.13.1, when `OIDCStripCookies` is set and a crafted cookie supplied, a NULL pointer dereference would occur, resulting in a segmentation fault. This could be use
debian
CVE-2021-20718P3HIGHCVSS 7.5fixed in libapache2-mod-auth-openidc 2.4.4.1-2 (bookworm)2021
CVE-2021-20718 [HIGH] CVE-2021-20718: libapache2-mod-auth-openidc - mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-se...
mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 2.4.4.1-2)
bullseye: resolved (fixed in 2.4.4.1-2)
forky: resolved (fixed in 2.4.4.1-2)
sid: resolved (fixed in 2.4.4.1-2)
trixie: resolved (fixed in 2.4.4.1-2)
debian
CVE-2021-32786P4MEDIUMCVSS 4.7fixed in libapache2-mod-auth-openidc 2.4.9-1 (bookworm)2021
CVE-2021-32786 [MEDIUM] CVE-2021-32786: libapache2-mod-auth-openidc - mod_auth_openidc is an authentication/authorization module for the Apache 2.x HT...
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In versions prior to 2.4.9, `oidc_validate_redirect_url()` does not parse URLs the same way as most browsers do. As a result, this function can be b
debian
CVE-2021-39191P4MEDIUMCVSS 4.7fixed in libapache2-mod-auth-openidc 2.4.9.4-1 (bookworm)2021
CVE-2021-39191 [MEDIUM] CVE-2021-39191: libapache2-mod-auth-openidc - mod_auth_openidc is an authentication/authorization module for the Apache 2.x HT...
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In versions prior to 2.4.9.4, the 3rd-party init SSO functionality of mod_auth_openidc was reported to be vulnerable to an open redirect attack by s
debian
CVE-2021-32791P4MEDIUMCVSS 5.9fixed in libapache2-mod-auth-openidc 2.4.9-1 (bookworm)2021
CVE-2021-32791 [MEDIUM] CVE-2021-32791: libapache2-mod-auth-openidc - mod_auth_openidc is an authentication/authorization module for the Apache 2.x HT...
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9, the AES GCM encryption in mod_auth_openidc uses a static IV and AAD. It is important to fix because this c
debian
CVE-2021-32792P4LOWCVSS 3.1fixed in libapache2-mod-auth-openidc 2.4.9-1 (bookworm)2021
CVE-2021-32792 [LOW] CVE-2021-32792: libapache2-mod-auth-openidc - mod_auth_openidc is an authentication/authorization module for the Apache 2.x HT...
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9, there is an XSS vulnerability in when using `OIDCPreservePost On`.
Scope: local
bookworm: resolved (fixed in
debian
CVE-2022-23527P4MEDIUMCVSS 4.7fixed in libapache2-mod-auth-openidc 2.4.12.2-1 (bookworm)2022
CVE-2022-23527 [MEDIUM] CVE-2022-23527: libapache2-mod-auth-openidc - mod_auth_openidc is an OpenID Certified™ authentication and authorization module...
mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server. Versions prior to 2.4.12.2 are vulnerable to Open Redirect. When providing a logout parameter to the redirect URI, the existing code in oidc_validate_redirect_url() does not properly check for URLs that start with /\t, leading to an
debian
CVE-2019-20479P4MEDIUMCVSS 6.1fixed in libapache2-mod-auth-openidc 2.4.1-1 (bookworm)2019
CVE-2019-20479 [MEDIUM] CVE-2019-20479: libapache2-mod-auth-openidc - A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issu...
A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning.
Scope: local
bookworm: resolved (fixed in 2.4.1-1)
bullseye: resolved (fixed in 2.4.1-1)
forky: resolved (fixed in 2.4.1-1)
sid: resolved (fixed in 2.4.1-1)
trixie: resolved (fixed in 2.4.1-1)
debian
CVE-2019-14857P4MEDIUMCVSS 6.1fixed in libapache2-mod-auth-openidc 2.4.0.3-1 (bookworm)2019
CVE-2019-14857 [MEDIUM] CVE-2019-14857: libapache2-mod-auth-openidc - A flaw was found in mod_auth_openidc before version 2.4.0.1. An open redirect is...
A flaw was found in mod_auth_openidc before version 2.4.0.1. An open redirect issue exists in URLs with trailing slashes similar to CVE-2019-3877 in mod_auth_mellon.
Scope: local
bookworm: resolved (fixed in 2.4.0.3-1)
bullseye: resolved (fixed in 2.4.0.3-1)
forky: resolved (fixed in 2.4.0.3-1)
sid: resolved (fixed in 2.4.0.3-1)
trixie: resolve
debian
CVE-2019-1010247P4MEDIUMCVSS 6.1fixed in libapache2-mod-auth-openidc 2.3.10.2-1 (bookworm)2019
CVE-2019-1010247 [MEDIUM] CVE-2019-1010247: libapache2-mod-auth-openidc - ZmartZone IAM mod_auth_openidc 2.3.10.1 and earlier is affected by: Cross Site S...
ZmartZone IAM mod_auth_openidc 2.3.10.1 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Redirecting the user to a phishing page or interacting with the application on behalf of the user. The component is: File: src/mod_auth_openidc.c, Line: 3109. The fixed version is: 2.3.10.2.
Scope: local
bookworm: resolved (fixed i
debian