A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.
An exception is thrown from a function, but it is not caught.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Http_server | Apache | - (including) | - (including) |
Red Hat Enterprise Linux 8 | RedHat | mod_auth_openidc:2.3-8100020250426100353.489197e6 | * |
Red Hat Enterprise Linux 8.2 Advanced Update Support | RedHat | mod_auth_openidc:2.3-8020020250612174445.4cda2c84 | * |
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | RedHat | mod_auth_openidc:2.3-8040020250618101351.522a0ee4 | * |
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | RedHat | mod_auth_openidc:2.3-8060020250617090503.ad008a3a | * |
Red Hat Enterprise Linux 8.6 Telecommunications Update Service | RedHat | mod_auth_openidc:2.3-8060020250617090503.ad008a3a | * |
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | RedHat | mod_auth_openidc:2.3-8060020250617090503.ad008a3a | * |
Red Hat Enterprise Linux 8.8 Telecommunications Update Service | RedHat | mod_auth_openidc:2.3-8080020250617090716.63b34585 | * |
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | RedHat | mod_auth_openidc:2.3-8080020250617090716.63b34585 | * |
Red Hat Enterprise Linux 9 | RedHat | mod_auth_openidc-0:2.4.10-1.el9_6.2 | * |
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | RedHat | mod_auth_openidc-0:2.4.9.4-1.el9_0.3 | * |
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | RedHat | mod_auth_openidc-0:2.4.9.4-1.el9_2.3 | * |
Red Hat Enterprise Linux 9.4 Extended Update Support | RedHat | mod_auth_openidc-0:2.4.9.4-4.el9_4.2 | * |
Libapache2-mod-auth-openidc | Ubuntu | focal | * |
Libapache2-mod-auth-openidc | Ubuntu | oracular | * |