Lack of data validation In libapache2-mod-auth-openidc
Description
Mod_auth_openidc.c in the Ping Identity OpenID Connect authentication module for Apache (aka mod_auth_openidc) before 2.14 allows remote attackers to spoof page content via a malicious URL provided to the user, which triggers an invalid request.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 2.1.5-1 | ||
debian 12 | 2.1.5-1 | ||
debian 13 | 2.1.5-1 | ||
debian 14 | 2.1.5-1 | ||
rpm rhel7 | 0:1.8.8-5.el7 |
Aliases
1. 2. 3. 4. 5.