[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256040

 
 

909

 
 

199103

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2019-1300

ID: oval:org.secpod.oval:def:1601057Date: (C)2019-10-04   (M)2023-11-10
Class: PATCHFamily: unix




A text injection flaw was found in how mod_auth_openidc handled error pages. An attacker could potentially use this flaw to conduct content spoofing and phishing attacks by tricking users into opening specially crafted URLs. It was found that mod_auth_openidc did not properly sanitize HTTP headers for certain request paths. A remote attacker could potentially use this flaw to bypass authentication and access sensitive information by sending crafted HTTP requests

Platform:
Amazon Linux AMI
Product:
mod24_auth_openidc
Reference:
ALAS-2019-1300
CVE-2017-6059
CVE-2017-6413
CVE    2
CVE-2017-6413
CVE-2017-6059
CPE    1
cpe:/o:amazon:linux

© SecPod Technologies