Skip to main content

Vendor/product archive

openidc / mod_auth_openidc CVEs

Beta · best-effort

15 CVEs tagged to openidc / mod_auth_openidc0 Critical, 6 High, 8 Medium, 1 Low, 0 Unrated.

CVE-2023-28625

Published Apr 3, 2023

mod_auth_openidc is an authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In versions 2.0.0 thr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14857

Published Nov 26, 2019

A flaw was found in mod_auth_openidc before version 2.4.0.1. An open redirect issue exists in URLs with trailing slashes similar to CVE-2019-3877 in mod_auth_mellon.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1010247

Published Jul 19, 2019

ZmartZone IAM mod_auth_openidc 2.3.10.1 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Redirecting the user to a phishing page or interacting with the appl…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6059

Published Apr 12, 2017

Mod_auth_openidc.c in the Ping Identity OpenID Connect authentication module for Apache (aka mod_auth_openidc) before 2.14 allows remote attackers to spoof page content via a mali…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6413

Published Mar 2, 2017

The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.6 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeade…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6062

Published Mar 2, 2017

The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.5 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeade…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1