Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Debian 9: DLA-2298-1 Critical: OpenID Connect Module Issues

debian lts
Calendar Grey July 29, 2020
Dist Debian Esm H88
Debian LTS Advisory DLA-2300-2 tackles various vulnerabilities found in libapache2-mod-security impacting the Apache web server.
Several issues have been found in libapache2-mod-auth-openidc, the OpenID Connect authentication module for the Apache HTTP server

Summary

Several issues have been found in libapache2-mod-auth-openidc, the OpenID
Connect authentication module for the Apache HTTP server.

CVE-2019-14857

Insufficient validation of URLs leads to an Open Redirect
vulnerability. An attacker may trick a victim into providing
credentials for an OpenID provider by forwarding the request to an
illegitimate website.

CVE-2019-20479

Due to insufficient validatation of URLs an Open Redirect
vulnerability for URLs beginning with a slash and backslash could be
abused.

CVE-2019-1010247

The OIDCRedirectURI page contains generated JavaScript code that uses
a poll parameter as a string variable, thus might contain additional
JavaScript code. This might result in Criss-Site Scripting (XSS).


For Debian 9 stretch, these problems have been fixed in version
2.1.6-1+deb9u1.

We recommend that you upgrade your libapache2-mod-auth-openidc packages.

For the detailed security status of libapache2-mod-auth-openidc please
refer to

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: libapache2-mod-auth-openidc
Version: 2.1.6-1+deb9u1
CVE ID: CVE-2019-14857 CVE-2019-20479 CVE-2019-1010247

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here