mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server. Versions prior to 2.4.12.2 are vulnerable to Open Redirect. When providing a logout parameter to the redirect URI, the existing code in oidc_validate_redirect_url() does not properly check for URLs that start with /\t, leading to an open redirect. This issue has been patched in version 2.4.12.2. Users unable to upgrade can mitigate the issue by configuring mod_auth_openidc to only allow redirection when the destination matches a given regular expression with OIDCRedirectURLsAllowed.
CVSS Details
- CVSS 3.1 Base Score: 4.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade mod_auth_openidcUpgrade cjose-develUpgrade cjose | Nov 16, 2023 | Dec 14, 2022 |
| Centos_linux | — | Upgrade mod_auth_openidcUpgrade cjose-debuginfoUpgrade cjoseUpgrade mod_auth_openidc-debugsourceUpgrade mod_auth_openidc-debuginfoUpgrade cjose-debugsourceUpgrade cjose-devel | Nov 8, 2023 | Dec 14, 2022 |
| Debian | — | Upgrade libapache2-mod-auth-openidc | Jul 24, 2023 | Dec 14, 2022 |
| Oracle_linux | — | Upgrade cjose-develUpgrade cjoseUpgrade mod_auth_openidc | Nov 22, 2023 | Dec 14, 2022 |
| Redhat_linux | — | Upgrade mod_auth_openidc-debuginfoNo solution existsUpgrade mod_auth_openidc-debugsourceUpgrade cjose-develUpgrade cjoseUpgrade mod_auth_openidcUpgrade cjose-debugsourceUpgrade cjose-debuginfo | Nov 8, 2023 | Dec 14, 2022 |
| Suse | — | Upgrade apache2-mod_auth_openidc | Jan 31, 2023 | Dec 14, 2022 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Dec 14, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub