CVE-2021-39191

Description

mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In versions prior to 2.4.9.4, the 3rd-party init SSO functionality of mod_auth_openidc was reported to be vulnerable to an open redirect attack by supplying a crafted URL in the target_link_uri parameter. A patch in version 2.4.9.4 made it so that the OIDCRedirectURLsAllowed setting must be applied to the target_link_uri parameter. There are no known workarounds aside from upgrading to a patched version.

Risk Information

Base Score
6.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.332

Associated Vulnerability

VulnerabilityOS Platform
SUSE-SU-2021:3352-1(SUSE Linux Enterprise Server 12-SP5 ) apache2-mod_auth_openidc-2.4.0-3.23.1.x86_64.rpmLinux
SUSE-SU-2021:3352-1(SUSE Linux Enterprise Server 12-SP5 ) apache2-mod_auth_openidc-debuginfo-2.4.0-3.23.1.x86_64.rpmLinux
SUSE-SU-2021:3352-1(SUSE Linux Enterprise Server 12-SP5 ) apache2-mod_auth_openidc-debugsource-2.4.0-3.23.1.x86_64.rpmLinux
(RHSA-2022:1823) mod_auth_openidc:2.3 security update mod_auth_openidc-2.3.7-11.module+el8.6.0+14082+b6f23e95.x86_64.rpmLinux
(RHSA-2022:1823) mod_auth_openidc:2.3 security update mod_auth_openidc-debugsource-2.3.7-11.module+el8.6.0+14082+b6f23e95.x86_64.rpmLinux
mod_auth_openidc:2.3 security update (RLSA-2022:1823) cjose-0.6.1-2.module+el8.3.0+129+2feafa46.x86_64.rpmLinux
mod_auth_openidc:2.3 security update (RLSA-2022:1823) cjose-devel-0.6.1-2.module+el8.3.0+129+2feafa46.x86_64.rpmLinux
mod_auth_openidc:2.3 security update (RLSA-2022:1823) mod_auth_openidc-2.3.7-11.module+el8.6.0+840+73eca44e.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234