RHSA-2023:4418-01 -- Redhat cjose, mod_auth_openidcID: oval:org.secpod.oval:def:507874 | Date: (C)2023-08-10 (M)2023-11-06 |
Class: PATCH | Family: unix |
The mod_auth_openidc is an OpenID Connect authentication module for Apache HTTP Server. It enables an Apache HTTP Server to operate as an OpenID Connect Relying Party and/or OAuth 2.0 Resource Server. Security Fix: * cjose: AES GCM decryption uses the Tag length from the actual Authentication Tag provided in the JWE For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section.
Platform: |
Red Hat Enterprise Linux 8 |
Product: |
cjose |
mod_auth_openidc |