The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.6 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an "AuthType oauth20" configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic.
CVSS Details
- CVSS 3.0 Base Score: 8.6
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade mod_auth_openidcUpgrade mod_auth_openidc-debuginfo | Apr 27, 2020 | Mar 2, 2017 |
| Amazon_linux | — | Upgrade mod24_auth_openidc | Oct 4, 2019 | Mar 2, 2017 |
| Centos_linux | — | Upgrade mod_auth_openidcUpgrade mod_auth_openidc-debuginfo | Aug 28, 2019 | Mar 2, 2017 |
| Debian | — | Upgrade libapache2-mod-auth-openidc | Jul 30, 2024 | Mar 2, 2017 |
| Oracle_linux | — | Upgrade mod_auth_openidc | Jul 21, 2020 | Feb 20, 2017 |
| Redhat_linux | — | Upgrade mod_auth_openidcUpgrade mod_auth_openidc-debuginfo | Aug 7, 2019 | Mar 2, 2017 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Mar 2, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub