[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250108

 
 

909

 
 

196064

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2020-1538 --- mod_auth_openidc

ID: oval:org.secpod.oval:def:1700416Date: (C)2020-11-05   (M)2023-11-13
Class: PATCHFamily: unix




An open redirect flaw was discovered in mod_auth_openidc, where it handles logout redirection. The module does not correctly validate the URL, allowing a URL with leading slashes to bypass the protection checks. A victim user may be tricked into visiting a trusted vulnerable web site, which would redirect them to another possibly malicious URL. An open redirect flaw was discovered in mod_auth_openidc where it handles logout redirection. The module does not correctly validate the URL, allowing a URL with slash and backslash at the beginning to bypass the protection checks. A victim user may be tricked into visiting a trusted vulnerable web site, which would redirect him to another, possibly malicious, URL

Platform:
Amazon Linux 2
Product:
mod_auth_openidc
Reference:
ALAS2-2020-1538
CVE-2019-14857
CVE-2019-20479
CVE    2
CVE-2019-14857
CVE-2019-20479

© SecPod Technologies