Authentication Bypass in mod_auth_openidc Module for Apache HTTP Server
CVE-2017-6062

8.6HIGH

Key Information:

Vendor

Openidc

Vendor
CVE Published:
2 March 2017

What is CVE-2017-6062?

The mod_auth_openidc module for Apache HTTP Server prior to version 2.1.5 does not adequately handle OIDC_CLAIM_ and OIDCAuthNHeader headers in configurations where OIDCUnAuthAction is set to pass. This flaw allows remote attackers to submit crafted HTTP requests, potentially leading to unauthorized access and bypassing the intended authentication mechanisms.

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.