mod_auth_openidc core dump when OIDCStripCookies is set and an empty Cookie header is supplied
CVE-2023-28625

7.5HIGH

Key Information:

Vendor

Openidc

Vendor
CVE Published:
3 April 2023

What is CVE-2023-28625?

The mod_auth_openidc module for Apache HTTP Server, versions 2.0.0 through 2.4.13.1, is susceptible to a Denial of Service vulnerability. This occurs when the OIDCStripCookies option is enabled and a specifically crafted cookie is supplied. The resulting NULL pointer dereference leads to a segmentation fault, which can disrupt service availability. Users are advised to avoid using OIDCStripCookies and to upgrade to version 2.4.13.2 or later, where this issue has been patched.

Affected Version(s)

mod_auth_openidc >= 2.0.0, < 2.4.13.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.