Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-28625

Опубликовано: 03 апр. 2023
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

mod_auth_openidc is an authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In versions 2.0.0 through 2.4.13.1, when OIDCStripCookies is set and a crafted cookie supplied, a NULL pointer dereference would occur, resulting in a segmentation fault. This could be used in a Denial-of-Service attack and thus presents an availability risk. Version 2.4.13.2 contains a patch for this issue. As a workaround, avoid using OIDCStripCookies.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:openidc:mod_auth_openidc:*:*:*:*:*:*:*:*
Версия от 2.0.0 (включая) до 2.4.13.2 (исключая)

EPSS

Процентиль: 68%
0.01327
Низкий

7.5 High

CVSS3

Дефекты

CWE-476
CWE-476

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

mod_auth_openidc is an authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In versions 2.0.0 through 2.4.13.1, when `OIDCStripCookies` is set and a crafted cookie supplied, a NULL pointer dereference would occur, resulting in a segmentation fault. This could be used in a Denial-of-Service attack and thus presents an availability risk. Version 2.4.13.2 contains a patch for this issue. As a workaround, avoid using `OIDCStripCookies`.

CVSS3: 7.5
redhat
больше 3 лет назад

mod_auth_openidc is an authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In versions 2.0.0 through 2.4.13.1, when `OIDCStripCookies` is set and a crafted cookie supplied, a NULL pointer dereference would occur, resulting in a segmentation fault. This could be used in a Denial-of-Service attack and thus presents an availability risk. Version 2.4.13.2 contains a patch for this issue. As a workaround, avoid using `OIDCStripCookies`.

CVSS3: 7.5
msrc
около 3 лет назад

mod_auth_openidc core dump when OIDCStripCookies is set and an empty Cookie header is supplied

CVSS3: 7.5
debian
больше 3 лет назад

mod_auth_openidc is an authentication and authorization module for the ...

suse-cvrf
больше 3 лет назад

Security update for apache2-mod_auth_openidc

EPSS

Процентиль: 68%
0.01327
Низкий

7.5 High

CVSS3

Дефекты

CWE-476
CWE-476