Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 17

Количество 17

fstec логотип

BDU:2025-11077

больше 1 года назад

Уязвимость модуля аутентификации и авторизации для Apache 2.x HTTP server Mod_auth_openidc, связанная с раскрытием информации, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20251022-01

10 месяцев назад

Уязвимость mod_auth_openidc

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-31492

больше 1 года назад

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.16.11, a bug in a mod_auth_openidc results in disclosure of protected content to unauthenticated users. The conditions for disclosure are an OIDCProviderAuthRequestMethod POST, a valid account, and there mustn't be any application-level gateway (or load balancer etc) protecting the server. When you request a protected resource, the response includes the HTTP status, the HTTP headers, the intended response (the self-submitting form), and the protected resource (with no headers). This is an example of a request for a protected resource, including all the data returned. In the case where mod_auth_openidc returns a form, it has to return OK from check_userid so as not to go down the error path in httpd. This means httpd will try to issue the protected resource. oidc_content_handler is called early, whi...

EPSS: Низкий
redhat логотип

CVE-2025-31492

больше 1 года назад

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.16.11, a bug in a mod_auth_openidc results in disclosure of protected content to unauthenticated users. The conditions for disclosure are an OIDCProviderAuthRequestMethod POST, a valid account, and there mustn't be any application-level gateway (or load balancer etc) protecting the server. When you request a protected resource, the response includes the HTTP status, the HTTP headers, the intended response (the self-submitting form), and the protected resource (with no headers). This is an example of a request for a protected resource, including all the data returned. In the case where mod_auth_openidc returns a form, it has to return OK from check_userid so as not to go down the error path in httpd. This means httpd will try to issue the protected resource. oidc_content_handler is called early, whi...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-31492

больше 1 года назад

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.16.11, a bug in a mod_auth_openidc results in disclosure of protected content to unauthenticated users. The conditions for disclosure are an OIDCProviderAuthRequestMethod POST, a valid account, and there mustn't be any application-level gateway (or load balancer etc) protecting the server. When you request a protected resource, the response includes the HTTP status, the HTTP headers, the intended response (the self-submitting form), and the protected resource (with no headers). This is an example of a request for a protected resource, including all the data returned. In the case where mod_auth_openidc returns a form, it has to return OK from check_userid so as not to go down the error path in httpd. This means httpd will try to issue the protected resource. oidc_content_handler is called early, which

EPSS: Низкий
debian логотип

CVE-2025-31492

больше 1 года назад

mod_auth_openidc is an OpenID Certified authentication and authorizati ...

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:1465-1

около 1 года назад

Security update for apache2-mod_auth_openidc

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:1337-1

больше 1 года назад

Security update for apache2-mod_auth_openidc

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:1324-1

больше 1 года назад

Security update for apache2-mod_auth_openidc

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:1286-1

больше 1 года назад

Security update for apache2-mod_auth_openidc

EPSS: Низкий
rocky логотип

RLSA-2025:7490

10 месяцев назад

Important: mod_auth_openidc security update

EPSS: Низкий
rocky логотип

RLSA-2025:7419

10 месяцев назад

Important: mod_auth_openidc security update

EPSS: Низкий
rocky логотип

RLSA-2025:3997

около 1 года назад

Important: mod_auth_openidc:2.3 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7490

около 1 года назад

ELSA-2025-7490: mod_auth_openidc security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7419

около 1 года назад

ELSA-2025-7419: mod_auth_openidc security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-3997

больше 1 года назад

ELSA-2025-3997: mod_auth_openidc:2.3 security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4532-1

7 месяцев назад

Security update for apache2-mod_auth_openidc

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-11077

Уязвимость модуля аутентификации и авторизации для Apache 2.x HTTP server Mod_auth_openidc, связанная с раскрытием информации, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 7.5
1%
Низкий
больше 1 года назад
redos логотип
ROS-20251022-01

Уязвимость mod_auth_openidc

CVSS3: 7.5
1%
Низкий
10 месяцев назад
ubuntu логотип
CVE-2025-31492

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.16.11, a bug in a mod_auth_openidc results in disclosure of protected content to unauthenticated users. The conditions for disclosure are an OIDCProviderAuthRequestMethod POST, a valid account, and there mustn't be any application-level gateway (or load balancer etc) protecting the server. When you request a protected resource, the response includes the HTTP status, the HTTP headers, the intended response (the self-submitting form), and the protected resource (with no headers). This is an example of a request for a protected resource, including all the data returned. In the case where mod_auth_openidc returns a form, it has to return OK from check_userid so as not to go down the error path in httpd. This means httpd will try to issue the protected resource. oidc_content_handler is called early, whi...

1%
Низкий
больше 1 года назад
redhat логотип
CVE-2025-31492

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.16.11, a bug in a mod_auth_openidc results in disclosure of protected content to unauthenticated users. The conditions for disclosure are an OIDCProviderAuthRequestMethod POST, a valid account, and there mustn't be any application-level gateway (or load balancer etc) protecting the server. When you request a protected resource, the response includes the HTTP status, the HTTP headers, the intended response (the self-submitting form), and the protected resource (with no headers). This is an example of a request for a protected resource, including all the data returned. In the case where mod_auth_openidc returns a form, it has to return OK from check_userid so as not to go down the error path in httpd. This means httpd will try to issue the protected resource. oidc_content_handler is called early, whi...

CVSS3: 7.5
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-31492

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.16.11, a bug in a mod_auth_openidc results in disclosure of protected content to unauthenticated users. The conditions for disclosure are an OIDCProviderAuthRequestMethod POST, a valid account, and there mustn't be any application-level gateway (or load balancer etc) protecting the server. When you request a protected resource, the response includes the HTTP status, the HTTP headers, the intended response (the self-submitting form), and the protected resource (with no headers). This is an example of a request for a protected resource, including all the data returned. In the case where mod_auth_openidc returns a form, it has to return OK from check_userid so as not to go down the error path in httpd. This means httpd will try to issue the protected resource. oidc_content_handler is called early, which

1%
Низкий
больше 1 года назад
debian логотип
CVE-2025-31492

mod_auth_openidc is an OpenID Certified authentication and authorizati ...

1%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:1465-1

Security update for apache2-mod_auth_openidc

1%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:1337-1

Security update for apache2-mod_auth_openidc

1%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:1324-1

Security update for apache2-mod_auth_openidc

1%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:1286-1

Security update for apache2-mod_auth_openidc

1%
Низкий
больше 1 года назад
rocky логотип
RLSA-2025:7490

Important: mod_auth_openidc security update

1%
Низкий
10 месяцев назад
rocky логотип
RLSA-2025:7419

Important: mod_auth_openidc security update

1%
Низкий
10 месяцев назад
rocky логотип
RLSA-2025:3997

Important: mod_auth_openidc:2.3 security update

1%
Низкий
около 1 года назад
oracle-oval логотип
ELSA-2025-7490

ELSA-2025-7490: mod_auth_openidc security update (IMPORTANT)

около 1 года назад
oracle-oval логотип
ELSA-2025-7419

ELSA-2025-7419: mod_auth_openidc security update (IMPORTANT)

около 1 года назад
oracle-oval логотип
ELSA-2025-3997

ELSA-2025-3997: mod_auth_openidc:2.3 security update (IMPORTANT)

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:4532-1

Security update for apache2-mod_auth_openidc

7 месяцев назад

Уязвимостей на страницу