Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 41: FEDORA-2025-7d661758bd critical: mod_auth_openidc data leak

fedora
Calendar Grey April 17, 2025
Dist Fedora Esm H88
Update mod_auth_openidc in Fedora 41 tackles severe information exposure problem caused by OIDCProviderAuthRequestMethod POST transmissions.
REbase mod_auth_openidc-2.4.16.11 resolves CVE-2025-31492 - mod_auth_openidc allows OIDCProviderAuthRequestMethod POSTs to leak protected data

Summary

This module enables an Apache 2.x web server to operate as

an OpenID Connect Relying Party and/or OAuth 2.0 Resource Server.

Update Information:

REbase mod_auth_openidc-2.4.16.11 resolves CVE-2025-31492 - mod_auth_openidc allows OIDCProviderAuthRequestMethod POSTs to leak protected data

Change Log

* Tue Apr 8 2025 Tomas Halman - 2.4.16.11-1 Rebase to version 2.4.16.11 - Resolves: rhbz#2357672 - mod_auth_openidc-2.4.16.11 is available - Resolves: rhbz#2357849 - CVE-2025-31492 mod_auth_openidc allows OIDCProviderAuthRequestMethod POSTs to leak protected data

References

Fedora Update Notification FEDORA-2025-7d661758bd 2025-04-17 19:46:50.126349+00:00 Name : mod_auth_openidc Product : Fedora 41 Version : 2.4.16.11 Release : 1.fc41 URL : https://github.com/OpenIDC/mod_auth_openidc Summary : OpenID Connect auth module for Apache HTTP Server Description : This module enables an Apache 2.x web server to operate as an OpenID Connect Relying Party and/or OAuth 2.0 Resource Server.

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-7d661758bd' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: mod_auth_openidc
Product: Fedora 41
Version: 2.4.16.11
Release: 1.fc41
Summary: OpenID Connect auth module for Apache HTTP Server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here