[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2019-1329 --- mod_auth_openidc

ID: oval:org.secpod.oval:def:1700235Date: (C)2019-10-25   (M)2023-11-13
Class: PATCHFamily: unix




A text injection flaw was found in how mod_auth_openidc handled error pages. An attacker could potentially use this flaw to conduct content spoofing and phishing attacks by tricking users into opening specially crafted URLs.It was found that mod_auth_openidc did not properly sanitize HTTP headers for certain request paths. A remote attacker could potentially use this flaw to bypass authentication and access sensitive information by sending crafted HTTP requests.

Platform:
Amazon Linux 2
Product:
mod_auth_openidc
Reference:
ALAS2-2019-1329
CVE-2017-6059
CVE-2017-6413
CVE    2
CVE-2017-6413
CVE-2017-6059

© SecPod Technologies