Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-3032

Опубликовано: 29 июл. 2020
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2020-3032: mod_auth_openidc:2.3 security and bug fix update (MODERATE)

cjose [0.6.1-2]

  • fix concatkdf big endian architecture problem. Upstream issue #77.

[0.6.1-1]

  • upgrade to latest upstream 0.6.1

[0.5.1-3]

[0.5.1-2]

[0.5.1-1]

  • Initial packaging

mod_auth_openidc [2.3.7-4.3]

  • Actually apply the previous patch, sigh
  • Related: rhbz#1820666 - CVE-2019-14857 mod_auth_openidc:2.3/mod_auth_openidc: Open redirect in logout url when using URLs with leading slashes [rhel-8.2.0.z]
  • Related: rhbz#1820662 - CVE-2019-20479 mod_auth_openidc:2.3/mod_auth_openidc: open redirect issue exists in URLs with slash and backslash [rhel-8.2.0.z]

[2.3.7-4.2]

  • Fix the previous backport
  • Related: rhbz#1820666 - CVE-2019-14857 mod_auth_openidc:2.3/mod_auth_openidc: Open redirect in logout url when using URLs with leading slashes [rhel-8.2.0.z]
  • Related: rhbz#1820662 - CVE-2019-20479 mod_auth_openidc:2.3/mod_auth_openidc: open redirect issue exists in URLs with slash and backslash [rhel-8.2.0.z]

[2.3.7-4.1]

  • Resolves: rhbz#1820666 - CVE-2019-14857 mod_auth_openidc:2.3/mod_auth_openidc: Open redirect in logout url when using URLs with leading slashes [rhel-8.2.0.z]
  • Resolves: rhbz#1820662 - CVE-2019-20479 mod_auth_openidc:2.3/mod_auth_openidc: open redirect issue exists in URLs with slash and backslash [rhel-8.2.0.z]

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module mod_auth_openidc:2.3 is enabled

cjose

0.6.1-2.module+el8+5139+bcb28322

cjose-devel

0.6.1-2.module+el8+5139+bcb28322

mod_auth_openidc

2.3.7-4.module+el8.2.0+7637+70221d24.3

Oracle Linux x86_64

Module mod_auth_openidc:2.3 is enabled

cjose

0.6.1-2.module+el8+5139+bcb28322

cjose-devel

0.6.1-2.module+el8+5139+bcb28322

mod_auth_openidc

2.3.7-4.module+el8.2.0+7637+70221d24.3

Связанные CVE

Связанные уязвимости

rocky
почти 5 лет назад

Moderate: mod_auth_openidc:2.3 security and bug fix update

oracle-oval
больше 4 лет назад

ELSA-2020-3970: mod_auth_openidc security update (LOW)

CVSS3: 6.1
ubuntu
больше 5 лет назад

A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning.

CVSS3: 6.1
redhat
больше 5 лет назад

A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning.

CVSS3: 6.1
nvd
больше 5 лет назад

A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning.