Open Redirect Affecting mod_auth_openidc:2.3/mod_auth_openidc package, versions <0:2.4.9.4-5.module_el8.9.0+3631+0ced13d7


Severity

Recommended
0.0
medium
0
10

Based on AlmaLinux security rating.

Threat Intelligence

EPSS
0.91% (56th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ALMALINUX8-MODAUTHOPENIDC-6090986
  • published27 Nov 2023
  • disclosed7 Nov 2023

Introduced: 7 Nov 2023

CVE-2022-23527  (opens in a new tab)
CWE-601  (opens in a new tab)

How to fix?

Upgrade AlmaLinux:8 mod_auth_openidc:2.3/mod_auth_openidc to version 0:2.4.9.4-5.module_el8.9.0+3631+0ced13d7 or higher.
This issue was patched in ALSA-2023:6940.

NVD Description

Note: Versions mentioned in the description apply only to the upstream mod_auth_openidc:2.3/mod_auth_openidc package and not the mod_auth_openidc:2.3/mod_auth_openidc package as distributed by AlmaLinux. See How to fix? for AlmaLinux:8 relevant fixed versions and status.

mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server. Versions prior to 2.4.12.2 are vulnerable to Open Redirect. When providing a logout parameter to the redirect URI, the existing code in oidc_validate_redirect_url() does not properly check for URLs that start with /\t, leading to an open redirect. This issue has been patched in version 2.4.12.2. Users unable to upgrade can mitigate the issue by configuring mod_auth_openidc to only allow redirection when the destination matches a given regular expression with OIDCRedirectURLsAllowed.

CVSS Base Scores

version 3.1