Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-28625

Опубликовано: 03 апр. 2023
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

mod_auth_openidc is an authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In versions 2.0.0 through 2.4.13.1, when OIDCStripCookies is set and a crafted cookie supplied, a NULL pointer dereference would occur, resulting in a segmentation fault. This could be used in a Denial-of-Service attack and thus presents an availability risk. Version 2.4.13.2 contains a patch for this issue. As a workaround, avoid using OIDCStripCookies.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:openidc:mod_auth_openidc:*:*:*:*:*:*:*:*
Версия от 2.0.0 (включая) до 2.4.13.2 (исключая)

EPSS

Процентиль: 29%
0.00103
Низкий

7.5 High

CVSS3

Дефекты

CWE-476
CWE-476

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

mod_auth_openidc is an authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In versions 2.0.0 through 2.4.13.1, when `OIDCStripCookies` is set and a crafted cookie supplied, a NULL pointer dereference would occur, resulting in a segmentation fault. This could be used in a Denial-of-Service attack and thus presents an availability risk. Version 2.4.13.2 contains a patch for this issue. As a workaround, avoid using `OIDCStripCookies`.

CVSS3: 7.5
redhat
больше 2 лет назад

mod_auth_openidc is an authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In versions 2.0.0 through 2.4.13.1, when `OIDCStripCookies` is set and a crafted cookie supplied, a NULL pointer dereference would occur, resulting in a segmentation fault. This could be used in a Denial-of-Service attack and thus presents an availability risk. Version 2.4.13.2 contains a patch for this issue. As a workaround, avoid using `OIDCStripCookies`.

CVSS3: 7.5
debian
больше 2 лет назад

mod_auth_openidc is an authentication and authorization module for the ...

suse-cvrf
больше 2 лет назад

Security update for apache2-mod_auth_openidc

CVSS3: 7.5
redos
около 1 года назад

Уязвимость mod_auth_openidc

EPSS

Процентиль: 29%
0.00103
Низкий

7.5 High

CVSS3

Дефекты

CWE-476
CWE-476