Improper authorization control for web services In libapache2-mod-auth-openidc
Description
The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.5 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an "OIDCUnAuthAction pass" configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 14 | 2.1.5-1 | ||
debian 11 | 2.1.5-1 | ||
debian 12 | 2.1.5-1 | ||
debian 13 | 2.1.5-1 |
Aliases
1. 2. 3. 4. 5.