The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.6 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an "AuthType oauth20" configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic.
CVSS Details
- CVSS 3.0 Base Score: 8.6
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-mod_auth_openidcamazon-linux-ami-2-upgrade-mod_auth_openidc-debuginfo | Apr 27, 2020 | Mar 2, 2017 | |
| Amazon_linux | — | amazon-linux-upgrade-mod24_auth_openidc | Oct 4, 2019 | Mar 2, 2017 |
| Centos_linux | — | centos-upgrade-mod_auth_openidccentos-upgrade-mod_auth_openidc-debuginfo | Aug 28, 2019 | Mar 2, 2017 |
| Debian | debian-upgrade-libapache2-mod-auth-openidc | Jul 30, 2024 | Mar 2, 2017 | |
| Oracle_linux | — | oracle-linux-upgrade-mod-auth-openidc | Jul 21, 2020 | Feb 20, 2017 |
| Redhat_linux | — | redhat-upgrade-mod_auth_openidcredhat-upgrade-mod_auth_openidc-debuginfo | Aug 7, 2019 | Mar 2, 2017 |
| Ubuntu | no-fix-ubuntu-package | Jun 26, 2025 | Mar 2, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub