Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-3891

Опубликовано: 29 апр. 2025
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10mod_auth_openidcFix deferred
Red Hat Enterprise Linux 7mod_auth_openidcNot affected
Red Hat Enterprise Linux 8mod_auth_openidcFixedRHSA-2025:459706.05.2025
Red Hat Enterprise Linux 8.2 Advanced Update Supportmod_auth_openidcFixedRHSA-2025:1000601.07.2025
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportmod_auth_openidcFixedRHSA-2025:1000401.07.2025
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportmod_auth_openidcFixedRHSA-2025:1000301.07.2025
Red Hat Enterprise Linux 8.6 Telecommunications Update Servicemod_auth_openidcFixedRHSA-2025:1000301.07.2025
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutionsmod_auth_openidcFixedRHSA-2025:1000301.07.2025
Red Hat Enterprise Linux 8.8 Telecommunications Update Servicemod_auth_openidcFixedRHSA-2025:1001001.07.2025
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutionsmod_auth_openidcFixedRHSA-2025:1001001.07.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-248
https://bugzilla.redhat.com/show_bug.cgi?id=2361633mod_auth_openidc: DoS via Empty POST in mod_auth_openidc with OIDCPreservePost Enabled

EPSS

Процентиль: 71%
0.00707
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.

CVSS3: 7.5
nvd
3 месяца назад

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.

CVSS3: 7.5
debian
3 месяца назад

A flaw was found in the mod_auth_openidc module for Apache httpd. This ...

suse-cvrf
около 2 месяцев назад

Security update for apache2-mod_auth_openidc

suse-cvrf
около 2 месяцев назад

Security update for apache2-mod_auth_openidc

EPSS

Процентиль: 71%
0.00707
Низкий

7.5 High

CVSS3