mod_auth_openidc-2.4.9.4-4.el9

エラータID: AXSA:2023-6773:01

Release date: 
Thursday, December 7, 2023 - 17:42
Subject: 
mod_auth_openidc-2.4.9.4-4.el9
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
Moderate
Description: 

The mod_auth_openidc is an OpenID Connect authentication module for Apache HTTP Server. It enables an Apache HTTP Server to operate as an OpenID Connect Relying Party and/or OAuth 2.0 Resource Server.

Security Fix(es):

* mod_auth_openidc: Open Redirect in oidc_validate_redirect_url() using tab character (CVE-2022-23527)
* mod_auth_openidc: NULL pointer dereference when OIDCStripCookies is set and a crafted Cookie header is supplied (CVE-2023-28625)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2022-23527
mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server. Versions prior to 2.4.12.2 are vulnerable to Open Redirect. When providing a logout parameter to the redirect URI, the existing code in oidc_validate_redirect_url() does not properly check for URLs that start with /\t, leading to an open redirect. This issue has been patched in version 2.4.12.2. Users unable to upgrade can mitigate the issue by configuring mod_auth_openidc to only allow redirection when the destination matches a given regular expression with OIDCRedirectURLsAllowed.
CVE-2023-28625
mod_auth_openidc is an authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In versions 2.0.0 through 2.4.13.1, when `OIDCStripCookies` is set and a crafted cookie supplied, a NULL pointer dereference would occur, resulting in a segmentation fault. This could be used in a Denial-of-Service attack and thus presents an availability risk. Version 2.4.13.2 contains a patch for this issue. As a workaround, avoid using `OIDCStripCookies`.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. mod_auth_openidc-2.4.9.4-4.el9.src.rpm
    MD5: 1d9e221b4a8f7e7049bc32b061bce828
    SHA-256: 2f0576d7d429c78a2aa98f9dc1987ca503d5341b7d115d9fa0326912fe274129
    Size: 269.10 kB

Asianux Server 9 for x86_64
  1. mod_auth_openidc-2.4.9.4-4.el9.x86_64.rpm
    MD5: 74f78724e3306020b4b52b66f991688b
    SHA-256: 223278a95a10c6533ff3f0de16500233adecbf5d7766dcef648490e27893ba59
    Size: 193.40 kB