Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-3891

Опубликовано: 29 апр. 2025
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10mod_auth_openidcFix deferred
Red Hat Enterprise Linux 7mod_auth_openidcAffected
Red Hat Enterprise Linux 9mod_auth_openidcAffected
Red Hat Enterprise Linux 8mod_auth_openidcFixedRHSA-2025:459706.05.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-248
https://bugzilla.redhat.com/show_bug.cgi?id=2361633mod_auth_openidc: DoS via Empty POST in mod_auth_openidc with OIDCPreservePost Enabled

EPSS

Процентиль: 74%
0.00855
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.

CVSS3: 7.5
nvd
около 2 месяцев назад

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.

CVSS3: 7.5
debian
около 2 месяцев назад

A flaw was found in the mod_auth_openidc module for Apache httpd. This ...

suse-cvrf
5 дней назад

Security update for apache2-mod_auth_openidc

suse-cvrf
8 дней назад

Security update for apache2-mod_auth_openidc

EPSS

Процентиль: 74%
0.00855
Низкий

7.5 High

CVSS3