VYPR
Unrated severityNVD Advisory· Published Jul 26, 2021· Updated Aug 3, 2024

XSS vulnerability when using OIDCPreservePost On in mod_auth_openidc

CVE-2021-32792

Description

mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9, there is an XSS vulnerability in when using OIDCPreservePost On.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.