Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-3891

Опубликовано: 29 апр. 2025
Источник: debian
EPSS Низкий

Описание

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libapache2-mod-auth-openidcfixed2.4.14.2-1package

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2361633

  • https://github.com/OpenIDC/mod_auth_openidc/security/advisories/GHSA-x7cf-8wgv-5j86

  • Fixed by: https://github.com/OpenIDC/mod_auth_openidc/commit/29ea79dea97cdab1b0d150af2c9a50a442e7216e (v2.4.13.2)

EPSS

Процентиль: 74%
0.00855
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.

CVSS3: 7.5
redhat
около 2 месяцев назад

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.

CVSS3: 7.5
nvd
около 2 месяцев назад

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.

suse-cvrf
5 дней назад

Security update for apache2-mod_auth_openidc

suse-cvrf
8 дней назад

Security update for apache2-mod_auth_openidc

EPSS

Процентиль: 74%
0.00855
Низкий