mod_auth_openidc core dump when OIDCStripCookies is set and an empty Cookie header is supplied
CVE-2023-28625
7.5HIGH
What is CVE-2023-28625?
The mod_auth_openidc module for Apache HTTP Server, versions 2.0.0 through 2.4.13.1, is susceptible to a Denial of Service vulnerability. This occurs when the OIDCStripCookies option is enabled and a specifically crafted cookie is supplied. The resulting NULL pointer dereference leads to a segmentation fault, which can disrupt service availability. Users are advised to avoid using OIDCStripCookies and to upgrade to version 2.4.13.2 or later, where this issue has been patched.
Affected Version(s)
mod_auth_openidc >= 2.0.0, < 2.4.13.2
