ALAS2-2019-1329 --- mod_auth_openidcID: oval:org.secpod.oval:def:1700235 | Date: (C)2019-10-25 (M)2023-11-13 |
Class: PATCH | Family: unix |
A text injection flaw was found in how mod_auth_openidc handled error pages. An attacker could potentially use this flaw to conduct content spoofing and phishing attacks by tricking users into opening specially crafted URLs.It was found that mod_auth_openidc did not properly sanitize HTTP headers for certain request paths. A remote attacker could potentially use this flaw to bypass authentication and access sensitive information by sending crafted HTTP requests.