VYPR

rpm package

suse/apache2-mod_auth_openidc&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP4

pkg:rpm/suse/apache2-mod_auth_openidc&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4

Vulnerabilities (5)

  • CVE-2023-28625HigApr 3, 2023
    affected < 2.4.0-7.9.1fixed 2.4.0-7.9.1

    mod_auth_openidc is an authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In versions 2.0.0 through 2.4.13.1, when `OIDCStripCookies` is set and a crafted cookie supplied, a NULL pointer dereferen

  • CVE-2022-23527MedDec 14, 2022
    affected < 2.4.0-7.9.1fixed 2.4.0-7.9.1

    mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server. Versions prior to 2.4.12.2 are vulnerable to Open Redirect. When providing a logout parameter to the redirect URI, the existing code in oidc_validate_redirect_url() do

  • CVE-2021-20718HigMay 20, 2021
    affected < 2.4.0-3.14.1fixed 2.4.0-3.14.1

    mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vectors.

  • CVE-2019-20479MedFeb 20, 2020
    affected < 2.4.0-3.11.1fixed 2.4.0-3.11.1

    A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning.

  • CVE-2019-14857MedNov 26, 2019
    affected < 2.4.0-3.7.1fixed 2.4.0-3.7.1

    A flaw was found in mod_auth_openidc before version 2.4.0.1. An open redirect issue exists in URLs with trailing slashes similar to CVE-2019-3877 in mod_auth_mellon.