Open Redirect Vulnerability in mod_auth_openidc Affects Multiple Vendors
CVE-2019-20479

6.1MEDIUM

Key Information:

Vendor

Openidc

Vendor
CVE Published:
20 February 2020

What is CVE-2019-20479?

An open redirect vulnerability exists in mod_auth_openidc prior to version 2.4.1, which allows attackers to manipulate URLs containing a leading slash or backslash. This flaw may be exploited to redirect users to malicious sites without proper validation, potentially leading to phishing or other attacks. Users of affected versions are advised to update to the latest version to mitigate the risk associated with this security issue.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.