OS Command Injection In libapache2-mod-auth-openidc
Description
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9, there is an XSS vulnerability in when using OIDCPreservePost On.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 14 | 2.4.9-1 | ||
debian 11 | 2.4.9-1 | ||
debian 12 | 2.4.9-1 | ||
debian 13 | 2.4.9-1 | ||
rpm rhel8 | 0:2.3.7-11.module+el8.6.0+14082+b6f23e95 |
Aliases
1. 2. 3. 4. 5.