Authentication Bypass in Apache HTTP Server Module by Ping Identity
CVE-2017-6413

8.6HIGH

Key Information:

Vendor

Openidc

Vendor
CVE Published:
2 March 2017

What is CVE-2017-6413?

The mod_auth_openidc module for the Apache HTTP Server prior to version 2.1.6 contains a vulnerability that allows remote attackers to bypass authentication. This occurs due to improper handling of OIDC_CLAIM_ and OIDCAuthNHeader headers within an 'AuthType oauth20' configuration. Crafting specific HTTP requests enables malicious actors to circumvent authentication mechanisms, potentially compromising user accounts and sensitive data.

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.