Описание
ELSA-2020-3032: mod_auth_openidc:2.3 security and bug fix update (MODERATE)
cjose [0.6.1-2]
- fix concatkdf big endian architecture problem. Upstream issue #77.
[0.6.1-1]
- upgrade to latest upstream 0.6.1
[0.5.1-3]
[0.5.1-2]
[0.5.1-1]
- Initial packaging
mod_auth_openidc [2.3.7-4.3]
- Actually apply the previous patch, sigh
- Related: rhbz#1820666 - CVE-2019-14857 mod_auth_openidc:2.3/mod_auth_openidc: Open redirect in logout url when using URLs with leading slashes [rhel-8.2.0.z]
- Related: rhbz#1820662 - CVE-2019-20479 mod_auth_openidc:2.3/mod_auth_openidc: open redirect issue exists in URLs with slash and backslash [rhel-8.2.0.z]
[2.3.7-4.2]
- Fix the previous backport
- Related: rhbz#1820666 - CVE-2019-14857 mod_auth_openidc:2.3/mod_auth_openidc: Open redirect in logout url when using URLs with leading slashes [rhel-8.2.0.z]
- Related: rhbz#1820662 - CVE-2019-20479 mod_auth_openidc:2.3/mod_auth_openidc: open redirect issue exists in URLs with slash and backslash [rhel-8.2.0.z]
[2.3.7-4.1]
- Resolves: rhbz#1820666 - CVE-2019-14857 mod_auth_openidc:2.3/mod_auth_openidc: Open redirect in logout url when using URLs with leading slashes [rhel-8.2.0.z]
- Resolves: rhbz#1820662 - CVE-2019-20479 mod_auth_openidc:2.3/mod_auth_openidc: open redirect issue exists in URLs with slash and backslash [rhel-8.2.0.z]
Обновленные пакеты
Oracle Linux 8
Oracle Linux aarch64
Module mod_auth_openidc:2.3 is enabled
cjose
0.6.1-2.module+el8+5139+bcb28322
cjose-devel
0.6.1-2.module+el8+5139+bcb28322
mod_auth_openidc
2.3.7-4.module+el8.2.0+7637+70221d24.3
Oracle Linux x86_64
Module mod_auth_openidc:2.3 is enabled
cjose
0.6.1-2.module+el8+5139+bcb28322
cjose-devel
0.6.1-2.module+el8+5139+bcb28322
mod_auth_openidc
2.3.7-4.module+el8.2.0+7637+70221d24.3
Связанные CVE
Связанные уязвимости
A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning.
A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning.
A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning.